This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NickMikhal
NickMikhal Beginner
Beginner
since ‎2016-09-02
‎2021-04-14

User Statistics

  • 6 Posts
  • 0 Solutions
  • 3 Likes given
  • 0 Likes received
Announcement Banner

Users are unable to open Netwitness Support Cases via email. Please open support cases via portal or by phone

View Details
  • NetWitness Community
  • About NickMikhal

User Activity

  • Posts
  • Replies

ESA 11.3 falling sessions behind

by NickMikhal 2020-03-04 general.in NetWitness Discussions • latest reply by RohitUnnikrishn 2020-03-04
2020-03-04
Hello, We are experiencing ESA sessions behind with 11.3+ ESA and would like to seek advice of community on how to handle the issue. You can see previous thread covering 10.6 here: https://community.rsa.com/message/929061 Following RSA guide to reset...

Working with integers in LUA-NWDB

by NickMikhal 2019-04-16 general.in NetWitness Discussions • latest reply by WilliamMotley1 2019-05-13
2019-04-16
Good afternoon, I am working on LUA script on top of proxy parsers to extract ports from url's among other things.I have an issue working with integers, while strings are extracted properly.Not to post full script here are the main parts, which work ...

Re: ESA Alert Suppression MultiEvent Alerts

by NickMikhal 2019-08-26 general.in NetWitness Discussions
2019-08-26
Hello Lee, Thanks for the tip, but output first + "select * from Event" will suppress all events and in output I will have only the first event from the chain (somehow even if you are using.win:time_length_batch(60 minutes, 3)):Esper rule output:Inse...

Re: ESA Alert Suppression MultiEvent Alerts

by NickMikhal 2019-08-07 general.in NetWitness Discussions • latest reply by LeeKirkpatrick 2019-08-26
2019-08-07
Hello Lee,Thank you for your post it was very helpful! I was trying to achieve same results in means of output and suppression, however my pattern was different. All was fine except somehow 24 hour suppression was not working properly. My pattern for...

Re: Working with integers in LUA-NWDB

by NickMikhal 2019-05-13 general.in NetWitness Discussions
2019-05-13
Hello William,Thanks for the tip, did some modifications now the destination ports are extracted from url's properly. Handy for ftp over http extractions for example.Definition:nwlanguagekey.create("ip.dstport", nwtypes.UInt16)And additional check + ...

Re: ESA - Match on Multiple Occurrences of a Single Meta-Key?

by NickMikhal 2018-06-25 general.in NetWitness Discussions
2018-06-25
Hello Drew,First you change variable type of meta 'error' to string array: 000032359 - Changing ESA Variable Type in RSA Security Analytics 10.5 Then you use default string array operators with this meta: ALL, ANY, etc: Chapter 9. EPL Reference: Oper...
Likes given to
User Count
WilliamMotley1
Frequent Contributor WilliamMotley1 Frequent Contributor
1
rlaczkowski
rlaczkowski Occasional Contributor
1
SeanKoniarz
SeanKoniarz Beginner
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.