This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
ShishirKumar1
ShishirKumar1 Beginner
Beginner
since ‎2017-10-25
‎2021-04-14

User Statistics

  • 27 Posts
  • 0 Solutions
  • 4 Likes given
  • 1 Likes received
  • NetWitness Community
  • About ShishirKumar1

User Activity

  • Posts
  • Replies

ESM Syslog Template & Parsing

by ShishirKumar1 2019-12-13 general.in NetWitness Discussions • latest reply by JoshRandall 2020-01-07
2019-12-13
Hi All, We have recently moved to v11.3.1.1 on Netwitness and I am trying ot use the default Event Source monitoring to send syslog to one of our decoders when a device is inactive for a certain period of time. The default syslog template that is inc...

Problems with Windows event collection from Aggregators

by ShishirKumar1 2019-03-01 general.in NetWitness Discussions • latest reply by ShishirKumar1 2019-03-21
2019-03-01
Hi All, I am currently trying to integrate windows aggregators in our environment. The problem that I am facing is related to the rolling of a channel for the windows logs. I have the following error in the logs:Log for channel Security may have roll...

ESA Lag - Sessions Behind constantly

by ShishirKumar1 2018-09-21 general.in NetWitness Discussions • latest reply by JohnKisner 2019-04-01
2018-09-21
Hi All, We are continuously facing issues related to ESA lag. THE ESA falls behind on specific concentrators and there is delay in alerting. We have a RSA case open for this as well and we are being helped there but also thought of asking this in the...

Unable to Export Logs From Investigate View

by ShishirKumar1 2018-09-20 general.in NetWitness Discussions • latest reply by ShishirKumar1 2018-10-02
2018-09-20
Hi All, We are unable to export any log from the investigate view. The job page shows the query is waiting but it never completes. Could you please suggest a solution?

Log Replay for File Based Sources

by ShishirKumar1 2018-09-11 general.in NetWitness Discussions • latest reply by SeanGriesheimer 2018-09-20
2018-09-11
Hi All, I am trying to test a parser that I have created for SAP. In the NWLPT tool, I have created the parser and it works all the logs are parsed . When I deploy this on my test system and try to replay logs (both via uploading the log file and via...
View more

Re: ESM Syslog Template & Parsing

by ShishirKumar1 2020-01-07 general.in NetWitness Discussions
2020-01-07
Hi Josh, Happy New Year and thanks for your response! Please find my reply inline: If all the IPs in that log are the same and all belong to the same device, why can the event not be used to trigger a health check on the device? - If this is the only...

Re: ESM Syslog Template & Parsing

by ShishirKumar1 2019-12-17 general.in NetWitness Discussions • latest reply by JoshRandall 2020-01-07
2019-12-17
Hi Josh, Thanks for the reply. Yes I have the CEF parser deployed and enabled like I mentioned before. Still all the information is not being parsed out. Leaving the parsing aside ( I could write a custom CEF parser if needed), there is another probl...

Re: Help with CEF custom fields

by ShishirKumar1 2019-12-13 general.in NetWitness Discussions • latest reply by MaximilianoCitt 2019-12-16
2019-12-13
Hi Max, The answer is there in the link shared by Williams above. Please find the info below: Override Existing CEF Tag to NetWitness Meta Tag Mapping For a Specific DeviceTo change existing CEF tag to NetWitness Meta key mapping defined in Extention...

Re: Problems with Windows event collection from Aggregators

by ShishirKumar1 2019-03-19 general.in NetWitness Discussions • latest reply by david_waugh 2019-03-21
2019-03-19
Hi David, Okay I will try that. But I had a question about the polling duration and polling interval, should the polling duration always be lesser than polling interval. For example, if I try polling interval of 10 s, what would you suggest the polli...

Re: Problems with Windows event collection from Aggregators

by ShishirKumar1 2019-03-18 general.in NetWitness Discussions • latest reply by david_waugh 2019-03-21
2019-03-18
Hi Eric, We are on 10.6.5.1 and so the Endpoint windows agent cannot be use I suppose. Sravan Koneti‌ - The queue shows zero 1 rabbitmq.log 01 shovel.checkpoint 01 shovel.cmdscript 01 shovel.file 01 shovel.odbc 01 shovel.syslog 01 shovel.windows 0 Bu...
View more
Likes from
User Count
DavidEagen
DavidEagen Beginner
1
View all
Likes given to
User Count
EricPartington
Employee EricPartington
1
DaveGlover
Trusted Contributor DaveGlover Trusted Contributor
1
AhmedTarek
Employee AhmedTarek
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.