Where is the mapping defined between NetWitness and syslog messages? For
example if I want to see a failed ssh login on a RedHat system I could
look for the following in /var/log/messages:# type=USER_AUTH# $msg
contains the following; ‘op=PAM’ exe=”/...