This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
JoshRandall
Valued Contributor JoshRandall Valued Contributor
Valued Contributor
since ‎2015-11-09
‎2021-09-30

User Statistics

  • 302 Posts
  • 28 Solutions
  • 125 Likes given
  • 240 Likes received
Captain
Frequent Flyer
Making Yourself at Home
Welcome Back!
View all badges
  • NetWitness Community
  • About JoshRandall

User Activity

  • Posts
  • Replies

NetWitness Endpoint Meta Primer

by JoshRandall 2021-08-16 general.in NetWitness Community Blog
2021-08-16
The NetWitness Endpoint meta schema, while fully accessible, has remained a mostly opaque and little understood topic. Exactly what metadata gets created, where from, and how to modify/customize the schema is not something that we have provided any e...

Using a 3rd Party Certificate with Endpoint 11.4 - The Hard Way

by JoshRandall 2020-08-06 general.in NetWitness Community Blog
2020-08-06
By default, NetWitness Endpoint 11.x creates a self-signed Certificate Authority during its initial installation, and uses this CA to generate certificates for the endpoint agent and the local reverse proxy that handles all incoming agent communicati...

Using a 3rd Party Certificate with Endpoint 11.4 - The Easy Way

by JoshRandall 2020-08-06 general.in NetWitness Community Blog
2020-08-06
By default, NetWitness Endpoint 11.x creates a self-signed Certificate Authority during its initial installation, and uses this CA to generate certificates for the endpoint agent and the local reverse proxy that handles all incoming agent communicati...

Postman for NetWitness

by JoshRandall 2020-05-17 general.in NetWitness Community Blog • latest reply by JoshRandall 2020-08-18
2020-05-17
If you've ever done any work testing against an API (or even just for fun), then you've likely come across a number of tools that aim to make this work (or fun) easier. Postman is one of these tools, and one of its features is a method to import and ...

Custom Flat File Log Collection with NW-Endpoint 11.4

by JoshRandall 2020-04-22 general.in NetWitness Community Blog • latest reply by Nijo 2022-02-15
2020-04-22
22APR2020 - UPDATE: Naushad Kasu‌ has posted a video blog of this process and I have posted the template.xml and NweAgentPolicyDetails_x64.exe files from his blog here. 08APR2020 - UPDATE: adding a couple notes and example typespecs after some additi...
View more

Re: EPL: context with enrichment

by JoshRandall 2021-09-14 general.in NetWitness Discussions • latest reply by BohdanR 2021-09-14
2021-09-14
@BohdanR I don't know if there's a way to use both a CH List and a context at the same time, but you can use local time zone offsets in your contexts like so.... CREATE SCHEMA BeginNonWorkingHours(); CREATE SCHEMA EndNonWorkingHours(); CREATE CONTEXT...

Re: Active directory Authentication with RSA Netwitness

by JoshRandall 2021-09-09 general.in NetWitness Discussions
2021-09-09
@Hitachi_L3 You assign permissions to Roles and External Group Mappings, not to individual users. Users with those roles will receive the assigned permissions.

Re: Active directory Authentication with RSA Netwitness

by JoshRandall 2021-09-08 general.in NetWitness Discussions
2021-09-08
@Hitachi_L3 It's only possible to add external AD security groups, not individual user accounts. But you can certainly assign multiple roles to the external group - simply need to keep adding them to the group within the Admin/Security --> External G...

Re: Cisco Sourcefire

by JoshRandall 2021-08-20 general.in NetWitness Discussions
2021-08-20
If the logs that do not have the sig.id parsed are all being handled by msg.id "Snort_AlertLog" then you'd only need to add/modify that. But if those events are being handled by other msg.ids then you'd likely want/need to modify those others, as wel...

Re: Advance workflow configuration

by JoshRandall 2021-08-19 general.in NetWitness Discussions
2021-08-19
@Ripudaman03 that sounds like an Archer question - this is the NetWitness product space.
View more
Likes from
User Count
pmk2
pmk2 Trailblazer
1
DnielTvaj
DnielTvaj Trailblazer
4
immadn
Consumer immadn Consumer
1
EdPadilla
EdPadilla Occasional Contributor
1
EricSchwartz
EricSchwartz Occasional Contributor
1
View all
Likes given to
User Count
RichardB
RichardB Frequent Contributor
2
JeremyKerwin
JeremyKerwin Valued Contributor
1
LeeKirkpatrick
Valued Contributor LeeKirkpatrick Valued Contributor
3
MaximMarchenko
MaximMarchenko Occasional Contributor
1
Maciej
Maciej New Contributor
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.