Hi, If you have only NW Server deployed, the respond-server will be
offline. Respond server needs an ESA Primary Host to be added the
environment. Respond server uses mongo instance on ESA Primary host to
write application data.
Hi, Log Collector or rather rabbitmq stores the queued messages on disk
in /var/lib/rabbitmq/mnesia/sa@/msg_store_persistent. It gets
written to disk until the /var/netwitness partition gets full. You will
start seeing rabbitmq disk threshold warning...
Hi @susui Original alerts are basically raw alerts respond receives from
ESA. Once the raw alert comes into respond, it goes through a process
called normalization which is basically mapping fields from raw alert to
user known meta keys. The end aler...
Hi Sanjiv, I don't think we support any exceptions as of now. Any
changes made under Security -> Settings will apply to all users in NW.
Please raise an Enhancement ticket if you feel so after contacting with