This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
CHADHEILIG
CHADHEILIG Beginner
Beginner
since ‎2015-10-14
‎2021-04-13

User Statistics

  • 13 Posts
  • 1 Solutions
  • 1 Likes given
  • 0 Likes received
First Reply
Conversationalist
Break the Ice
1st Solution
View all badges
  • NetWitness Community
  • About CHADHEILIG

User Activity

  • Posts
  • Replies

Adding Log Concentrators to ESA gives org.apache.mina error

by CHADHEILIG 2014-04-24 general.in NetWitness Discussions • latest reply by CHADHEILIG 2014-04-30
2014-04-24
When conencting Log Concentrators to ESA I am getting:Failed to connect to x.x.x.x:50005 org.apache.mina.core.RuntimeIoException: Failed to create a new instance of org.apache.mina.transport.socket.nio.NioProcessor:null The Packet Decoders can connec...

Custom Dashboard 'not enough permissions'

by CHADHEILIG 2014-02-18 general.in NetWitness Discussions • latest reply by CHADHEILIG 2014-03-23
2014-02-18
Having issues with a custom dashboard. Have imported the rules and charts, enabled them and set them to the appropriate broker. Charts and Rules were tested and permissions were set correctly. Uploaded the newdashboard.cfg file but get the error: 'Yo...

Re: If it bleeds...we can kill it!

by CHADHEILIG 2017-11-02 general.in NetWitness Community Blog
2017-11-02
I have some traffic being triggered on analysis.service = 'http invalid allow methods', but the 'access-control-allow-methods' are the following: Access-Control-Allow-Methods: * and nothing with an http response of Allow:And then I have traffic being...

Re: If it bleeds...we can kill it!

by CHADHEILIG 2017-11-02 general.in NetWitness Community Blog
2017-11-02
That gives a lot of information to pivot on if you are in Investigation. But if we want to create an app rule, or esa rule to trigger on this traffic just the analysis.service meta doesn't have any use. Is there any additional specific meta that is t...

Re: If it bleeds...we can kill it!

by CHADHEILIG 2017-11-02 general.in NetWitness Community Blog
2017-11-02
If the functionality of the options_bleed.lua parser has been included in the HTTP_lua we don't need the options_bleed.parser. But the options_bleed_apprule triggered on analysis.session='garbled http options allow string' && service = 80 && action =...

Re: Does anyone have Cisco firepower manager custom Parsers created?

by CHADHEILIG 2017-10-11 general.in NetWitness Discussions
2017-10-11
The logs for Dropped: Correlation Event and Not Dropped: Correlation (custom) gets parsed with snort parser (Header 0026 / message Snort_Alert.log). But the portion of the log that we need pulled (the Dropped / Not Dropped) is parsed as hfld1. And th...

Re: Does anyone have Cisco firepower manager custom Parsers created?

by CHADHEILIG 2017-10-10 general.in NetWitness Discussions
2017-10-10
We are about to go through the same thing. The logs from the Firepower is getting parsed as unknown,snort or ciscorouter and not getting parsed correctly. Going to try to utilize the ESI tool to create a custom parser and map it directly to the IP of...
View more
Likes given to
User Count
RSAAdmin
RSAAdmin Beginner
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.