This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
DavidWaugh1
Employee DavidWaugh1
Employee
since ‎2015-12-18
‎2021-04-13

User Statistics

  • 297 Posts
  • 21 Solutions
  • 24 Likes given
  • 263 Likes received
  • NetWitness Community
  • About DavidWaugh1

User Activity

  • Posts
  • Replies

Monitoring Netwitness with Zabbix

by DavidWaugh1 2017-03-17 general.in NetWitness Community Blog • latest reply by DavidWaugh1 2017-03-20
2017-03-17
This post is completely unsupported by RSA Support and indeed RSA, but it might be interesting if you want to try it. In Netwitness 10.X the current weakness in the topology is that the SA Server is a single point of failure and it monitors the other...

Where can I find the 10.6.2.2 Download?

by DavidWaugh1 2017-03-14 general.in NetWitness Discussions • latest reply by jeffshurtliff 2017-03-15
2017-03-14
If you are having problems finding the 10.6.2.2 download then it can be reached here: https://community.rsa.com/docs/DOC-72942

Nagios Script to Check Sessions Behind on a ESA

by DavidWaugh1 2017-02-03 general.in NetWitness Community Blog • latest reply by YoussefARIF 2017-03-27
2017-02-03
Unfortunately its not currently possible to see if the maximum sessions behind on an ESA easily. This script enables it to be monitored. Usage:./check_esa_sessions_behind.sh -w VALUE -c VALUE | -hThis plug-in is used to be alerted when maximum ESA be...

Extracting Event Time from Logs

by DavidWaugh1 2017-01-24 general.in NetWitness Community Blog • latest reply by DavidWaugh1 2017-02-03
2017-01-24
Last Updated: 12:41 February 27th 2017Latest Version: 17 I had a customer who wishes to extract the raw event time for particular logs. This is because they use this raw event time for further analysis of events in a third party system. The raw event...

LUA Parser to deal with Alternative Syslog formats

by DavidWaugh1 2017-01-13 general.in NetWitness Community Blog
2017-01-13
I have a customer who use something called a "Data Diode" to enforce one way connectivity through their network.One result of this is that any syslog that is being sent through the diode gets its device IP changed. For example any message that was se...
View more

Re: Funny problem: too many events

by DavidWaugh1 2017-05-19 general.in NetWitness Discussions • latest reply by RomanZeltser 2017-05-19
2017-05-19
Hi Roman, You need to go to the log or packet decoder and then select config. App Rules can then be configured on the App Rules tab.

Re: Installation of RSA SA

by DavidWaugh1 2017-04-29 general.in NetWitness Discussions
2017-04-29
Hello without services I think you are setting up your project for failure. Here is my prediction:1 you have problems implementing leading to multiple support calls2 this leads to the project deadlines being missed3 you get increasingly dissatisfied ...

Re: Installation of RSA SA

by DavidWaugh1 2017-04-28 general.in NetWitness Discussions • latest reply by ShaktiPrateekSh 2017-05-02
2017-04-28
Hello Thanks for using Netwitness and welcome to the forum. Unfortunately Netwitness is a complex product and I wouldn't describe it as a product that you can just purchase off the shelf and install it by following a series of manuals. I would strong...

Re: NXLOG Windows Collection Support

by DavidWaugh1 2017-04-26 general.in NetWitness Discussions • latest reply by huanzhou1 2018-02-08
2017-04-26
Is using winrm as a collection method an alternative?I would have thought it was easier to set up as it can be controlled via domain policy and also scripted to be deployed in large environments.

Re: LUA Parser to detect and alert if CheckPoint logs are falling behind

by DavidWaugh1 2017-04-19 general.in NetWitness Discussions
2017-04-19
There have been a few changes to the checkpoint parser, which means the original parser posted here also needs to be updated. Bascially the time in the log is now in fld85. After updating your CheckPoint parser from Live please ensure: 1. Change the ...
View more
Likes from
User Count
Anonymous
52
MaximilianoCitt
MaximilianoCitt Frequent Contributor
2
KEVINDIENST
KEVINDIENST Beginner
3
IslamRashad
Employee IslamRashad
2
AnujShrivastava
AnujShrivastava Beginner
1
View all
Likes given to
User Count
ChrisThomas
ChrisThomas Frequent Contributor
1
HalimAbouzeid
Respected Contributor HalimAbouzeid Respected Contributor
1
LeeKirkpatrick
Valued Contributor LeeKirkpatrick Valued Contributor
2
jAMESHERBST
jAMESHERBST Beginner
1
KEVINDIENST
KEVINDIENST Beginner
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.