This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Platform Product Advisories
Read and subscribe to the latest announcements and advisories relating to the NetWitness Platform.
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • NetWitness Community
  • Products
  • NetWitness Platform
  • Advisories
  • Product Advisories
  • NetWitness announces the release of NetWitness Platform 12.3
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Printer Friendly Page
    • Report Inappropriate Content
NetWitness announces the release of NetWitness Platform 12.3

NetWitness announces the release of NetWitness Platform 12.3

NetWitness is pleased to announce the general availability of NetWitness Platform 12.3. This release contains features to enhance visibility into remote workers and cloud infrastructures with SASE integration, network asset discovery and ranking through NetWitness Insight, multiple new log integrations, enhanced threat detection and response capabilities, and continued security updates.

 

NetWitness Platform 12.3 includes the following notable enhancements.

 

Visibility:

  • SASE Integrations – Available in preview mode, this new integration with major SASE vendors provides further network visibility for NetWitness Network (NDR) customers. Previously limited to logs, these integrations deliver original network traffic to NetWitness, providing analysts with deep visibility and detection for SASE remote communications. Please contact your account representative to get a preview.
  • Splunk Integrations – Bidirectional workflow allows data flow between NetWitness and Splunk for additional context and increased efficiency. 
  • Zscaler ZIA/ZPA logs Integrations – Collect and parse Zscaler ZIA/ZPA logs to gain visibility into remote user and network activity across a Zscaler SASE infrastructure.
  • AWS AppFabric Integration - NetWitness has always led the way in extending visibility to new technology and solutions.  As a launch partner for AWS AppFabric, NetWitness empowers customers to use this simplified, standardized method of securing new and existing AWS apps.
  • FluentD Integration – Enhances security by consuming and monitoring additional, previously inaccessible log types with Logstash FluentD plugin.
  • Log Integrations – NetWitness supports Azure Kubernetes, Symantec Data Center and Jamf Protect integrations for security, system and audit logs ingestion to gain increased visibility across cloud workloads and endpoints.
  • IIS File Collection – Simplify endpoint log collection and increase visibility into Windows IIS logs.

 

Detection:

  • Netwitness Insight – Passive network asset discovery that automatically finds, prioritizes, and detects enterprise assets along with changes to them over time. Directs analysts’ attention to risks that matter most with complete visibility into the assets to be defended, with those assets ranked to enable quick decisions on the priority and criticality of an investigation.
  • Endpoint Remote Shell to Windows Agents – Analysts gain granular access to endpoint agents to take faster remediation actions.
  • Advanced Endpoint Linux agent – Analyst now has increased visibility into Linux process event activities as well as file event collections to detect threats on Linux machines.
  • Block Known File Hashes – Improved analyst workflow and response action by allowing bulk import of file hashes for endpoint agents to block.
  • Alert Generation from Core – Adds support for direct alert generation from core using application rules for improved efficiency.

 

Analysis:

  • Investigation Interactive Timeline – Accelerates time for analysts to create a query by using an interactive visual timeline.
  • Investigation Advanced Query Input – Allows analysts to drill deeper with guided advanced query functionality and improves overall investigation capabilities.
  • Alerting and Reporting  – Ability to turn investigating queries into actionable alerts and reports with streamlined workflows.
  • Meta Settings Panel – New Meta Settings Panel allows further control of the number of sessions analysts would like to investigate.
  • Alert Whitelisting – Analysts and Administrators can whitelist non-suspicious endpoint alerts and reduce future alert-exhaustion.

 

Administration:

  • Policy Based Centralized Content Management – Centralized Content Management (CCM) simplifies and saves time by adding support for automatic migration of content from core services and association with Policy that can be applied to Group of devices. CCM provides the ability to enable and disable CCM for individual services. In addition, CCM provides the ability to manage ESA rules and deployments with options for fast deployment.
  • Service Topology Export – Admins can not only view detailed network relationship maps between different aggregating services, they also will be able to export the relationship in JSON for reporting and integration.
  • Storage Compression using Zstandard - Enhances storage compression for better storage retention.
  • Support for Multiple UEBA Servers – Administrators can deploy multiple UEBA servers in their environment for load balancing and increased control.

 

Security:

  • Security updates – Addresses latest security vulnerabilities reported against various libraries used by the product.

 

 

Please refer to NetWitness Platform 12.3 Release Notes  for cipher changes and other update instructions.

 

For additional documentation, downloads, and more, visit the NetWitness Platform page on RSA Link.

Labels (3)
Labels:
  • Advisories

  • Product Advisories

  • Version 12.0

50 Likes
Was this article helpful? Yes No
No ratings

In this article

Version history
Last update:
4 weeks ago
Updated by:
Moderator RaviAdireddi Moderator

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.