This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
ShawnOstapuk
ShawnOstapuk Beginner
Beginner
since ‎2016-01-15
‎2021-04-13

User Statistics

  • 7 Posts
  • 0 Solutions
  • 2 Likes given
  • 2 Likes received
Announcement Banner

Users are unable to open Netwitness Support Cases via email. Please open support cases via portal or by phone

View Details
  • NetWitness Community
  • About ShawnOstapuk

User Activity

  • Posts
  • Replies
No posts to display.

Re: nwindex file size

by ShawnOstapuk 2016-11-04 general.in NetWitness Discussions • latest reply by NaushadKasu1 2016-11-20
2016-11-04
I think that is not correct. Meta that is IndexNone should not have an nwindex file at all. IndexKey is 448 bytes and IndexValues will vary depending on how many unique values there are. The actual list of sessions associated with each key is stored ...

Re: Custom Parser is working as Expected

by ShawnOstapuk 2016-07-29 general.in NetWitness Discussions
2016-07-29
David Waugh is correct. If the environment is small enough you could probably increase the max values for event.description and you will be good to go. If you have a large environment I would avoid using event.description in any parser. It is a gener...

Re: Windows Events - Fwd w/ milliseconds

by ShawnOstapuk 2016-07-29 general.in NetWitness Discussions
2016-07-29
If he's talking about decoder forwarding i would think it wouldn't be a problem it should be raw... If he means time meta (ie: event.time) does not support milliseconds, its 8 bytes that store epoch. You could try storing time in a Text value instead...

Re: How to include additional attributes like custom1 and custom2 in event source monitoring template.

by ShawnOstapuk 2016-07-29 general.in NetWitness Discussions
2016-07-29
If I'm understanding your question correctly, you can't. If you're goal (as an example) is to say monitor for device.type AND msg.id to look for specific events not coming it doesn't work that way. Someone can correct me if I'm wrong, but essentially...

Re: Visual Investigations

by ShawnOstapuk 2016-07-25 general.in NetWitness Discussions
2016-07-25
I would like to see support for trending multiple values. For example, to right click on a signature meta for IPS alerts and have a different colored line for each signature value so i can understand the breakdown of multiple values over time. That's...
View more
Likes from
User Count
jeffshurtliff
Administrator jeffshurtliff Administrator
1
ThomasJones1
Respected Contributor ThomasJones1 Respected Contributor
1
View all
Likes given to
User Count
DavidWaugh1
Employee DavidWaugh1
1
MihaMesojedec
Employee MihaMesojedec
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.