Looking to see if anyone knows if there is an advantage to the new Cisco
Umbrella connector vs the legacy collector for umbrella? We have quite a
few customers deployed with umbrella, so this will take a bit to
overhaul and move these customers from ...
Does the Netwitness Endpoint Agent stop any processes from processing if
you haven't manually blocked the file? Seeing this in the logs of one of
our files: Could not copy "obj\Debug\xxxxxxxxxxxxxxxxx.exe" to
Does anyone have experience with best practices around either building
APP Rules as a "Whitelist" or assigning a List to an APP Rule for
whitelisting purposes. We get an abundance of alerts for Powershell for
example, well many of these param.src / p...
I am getting this error, sure it is probably a simple fix so I am
posting it to the blog.....Anyone have any steps... We are using the
11.5 OVA, we are running 22.214.171.124 currently.
Best way I have found to create a rule that is effective is to first
find the traffic that you are looking to alert on. Once you find that
data then you can find the appropriate meta that would fire associated
with the traffic. This way you can also ...
Thank you for this info. This client was running the 11.5 agent. We had
them remove the 11.5 and install the 11.6.1 agent and this problem is
resolved. I think the issue becomes that the agent needs to stay up to
date. With the new releases of the NW...
The support team was able to get me the OVA for 11.6. Instantly with
quick ticket we recieved the FTP download. This also resolved the issue.
So when loading a hyrbid, the matching series OVA needs to match the
repository. You can check this by doing...