This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
KEVINDIENST
KEVINDIENST Beginner
Beginner
since ‎2014-10-15
‎2021-04-14

User Statistics

  • 76 Posts
  • 4 Solutions
  • 76 Likes given
  • 21 Likes received
  • NetWitness Community
  • About KEVINDIENST

User Activity

  • Posts
  • Replies

Remove session, meta and raw log data from Archivers

by KEVINDIENST 2019-01-15 general.in NetWitness Discussions • latest reply by NaushadKasu1 2019-01-31
2019-01-15
I am trying to find a method where I can remove unneeded data from our archivers. Idea:Run nwconsole (sdk content command) on all Archivers and output sessionid list that match where clause device.type = 'unknown'Feed that sessionid list to wipe SDK ...

Ability to upload custom internally signed certificate for web interface?

by KEVINDIENST 2018-11-30 general.in NetWitness Discussions • latest reply by KEVINDIENST 2019-01-15
2018-11-30
I don't see an option in the System or Security tab under ADMIN in v11.2 that allows me to upload a custom certificate for the web interface? I was under the impression this was an option in v11.2?

How to escape backslash CEF parser audit logging in NetWitness

by KEVINDIENST 2018-05-22 general.in NetWitness Discussions • latest reply by EricPartington 2018-09-18
2018-05-22
Scenario:We have CEF audit logging enabled. Usernames are not parsed correctly since it removes the backslash for the active directory domain and concatenates the domain and username. i.e. Domain is CONTOSOUsername is BLARGH result for user.src in CE...

Active Directory Integration?

by KEVINDIENST 2018-02-07 general.in NetWitness Discussions • latest reply by KEVINDIENST 2018-02-12
2018-02-07
From what I can tell the Investigator client only can leverage local accounts to the broker/concentrator service. Is that correct?

Syslog Event Filtering via Log Collector

by KEVINDIENST 2018-01-24 general.in NetWitness Discussions
2018-01-24
Log Collection Config: Configure Event Filters for Log Collector I'm a bit confused. I read the above documentation but if for instance, I have kernel warning logs from Syslog, so facility is kernel but severity is 'warning' then what sort of format ...
View more

Re: Remove session, meta and raw log data from Archivers

by KEVINDIENST 2019-01-15 general.in NetWitness Discussions
2019-01-15
OK, I'll try to use the nwget-logs.py script instead to pull those sessionids, but yeah, if the wipe command doesn't actually wipe that session, well... Thank you

Re: Ability to upload custom internally signed certificate for web interface?

by KEVINDIENST 2019-01-15 general.in NetWitness Discussions
2019-01-15
Update: I got it working in UAT, had to cat the root and issuing CA .cer (base64) format files in proper order to a single file called .chain and used that to convert the server .crt/.pem file into .p7b. openssl crl2pkcs7 -nocrl -certfile /root/web-s...

Re: Interesting DNS Tunneling Content

by KEVINDIENST 2019-01-07 general.in NetWitness Discussions
2019-01-07
I'm deploying this to my UAT and DR environments as I type this! I'm excited, thank you for doing this leg-work Matt. I'll provide feedback if I have any or have questions.

Re: Ability to upload custom internally signed certificate for web interface?

by KEVINDIENST 2018-12-19 general.in NetWitness Discussions
2018-12-19
Thank you Naushad Kasu‌ I'll keep these in my notes, I plan to have this completed as soon as our freeze period is over.

Re: Ability to upload custom internally signed certificate for web interface?

by KEVINDIENST 2018-11-30 general.in NetWitness Discussions • latest reply by AaronMartin2 2019-01-15
2018-11-30
Thank you Aaron Martin‌! I was going through so many configuration PDFs trying to find it. I'm happy you migrated to nginx as the front-end web server/reverse proxy.
View more
Likes from
User Count
Anonymous
2
dougds
dougds New Contributor
1
BrianKeenan
BrianKeenan Beginner
1
jeffshurtliff
Administrator jeffshurtliff Administrator
3
MichaelSconzo
Employee MichaelSconzo
1
View all
Likes given to
User Count
NaushadKasu1
Trusted Contributor NaushadKasu1 Trusted Contributor
4
AlessioAlfonsi
Contributor AlessioAlfonsi Contributor
1
MatthewTharp1
Employee MatthewTharp1
2
LeeKirkpatrick
Valued Contributor LeeKirkpatrick Valued Contributor
2
EricPartington
Employee EricPartington
15
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.