This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
AnujShrivastava
AnujShrivastava Beginner
Beginner
since ‎2016-03-30
‎2021-04-13

User Statistics

  • 21 Posts
  • 1 Solutions
  • 3 Likes given
  • 3 Likes received
  • NetWitness Community
  • About AnujShrivastava

User Activity

  • Posts
  • Replies

Windows Logs collection using winrm with HTTPS without script

by AnujShrivastava 2017-05-05 general.in NetWitness Discussions • latest reply by NaushadKasu1 2017-06-22
2017-05-05
I have integrated 150 Servers Using winrm HTTP Integration Technique provided by RSA in documentation, but now i want to integrate AD with winrm HTTPS, while going through the Documentation i found this -" WinRM Diagnostic Tool " But But But... Is th...

What Rules/Use-case should i use to track Proxy and Firewall Activity

by AnujShrivastava 2017-04-27 general.in NetWitness Discussions • latest reply by ArthurCostigan1 2017-05-03
2017-04-27
Hi All, It would be great if someone share some good Use cases or Rules which i can build or use to track Firewall and Proxy Traffic, which helps me show my client that following are the malicious activity happening through their network. I have depl...

Rule to track Remote session followed by a Remote session.

by AnujShrivastava 2017-04-12 general.in NetWitness Discussions • latest reply by JohnKisner 2017-04-13
2017-04-12
Hi ,I need to create a Rule where i can track the Consecutive Remote Desktop activity, If a user Login to a Server using RDP and Consecutively logs into a another server from that same server using a RDP again, means "Remote session from a server and...

The messages file fills up the /var/log partition and prevents services from starting on an RSA Security Analytics

by AnujShrivastava 2017-03-23 general.in NetWitness Discussions • latest reply by JesseLyon 2017-04-27
2017-03-23
In our Project a completely virtual Security Analatics environment is deployed,/var/log partition in VLC get full each time and whole thing gets stuck, not sure why. I am new to Security Analytics and followed following two article but var/log still ...

050-103-CARSASA01

by AnujShrivastava 2016-09-07 general.in NetWitness Discussions • latest reply by KathleenBissonn 2016-09-20
2016-09-07
Hi all, i am preparing for RSA Security Analytics Certified administrator exam i need to know that how long the certification is valid for? 050-103-CARSASA01
View more

Re: Windows Snare Logging Via VLC

by AnujShrivastava 2018-02-07 general.in NetWitness Discussions
2018-02-07
its Rsyslog 7.0

Re: Windows Snare Logging Via VLC

by AnujShrivastava 2018-02-07 general.in NetWitness Discussions • latest reply by DaveGlover 2018-02-07
2018-02-07
this is what I want to achieve------A cisco asa is sending logs to syslog server, now i want to collect those logs from that syslog server, and i tried your templet but not able to see any logs on my vlc. VLC IP: 10.201.12.80ASA IP: 10.201.3.103 whic...

Re: Windows Snare Logging Via VLC

by AnujShrivastava 2018-02-07 general.in NetWitness Discussions
2018-02-07
only other syslogs from different event sources... like cyberArk i have also tested cyberark logs those are also syslog types... 14:52:35.010819 IP (tos 0x0, ttl 64, id 50323, offset 0, flags [DF], proto TCP (6), length 40)st-rsa-vlc.hmgt.net.shell >...

Re: Parse correct device.ip from forwarded logs

by AnujShrivastava 2018-02-07 general.in NetWitness Discussions
2018-02-07
David Waugh‌ Hi David, I am using Rsyslog v.7 and i am trying to forwared cisco asa logs from our syslog server to VLC.VLC IP: 10.201.12.80ASA IP: 10.201.3.103 -------------------------------is this correct ?------------------------$template NWLDfmt,...

Re: Windows Snare Logging Via VLC

by AnujShrivastava 2018-02-07 general.in NetWitness Discussions • latest reply by DaveGlover 2018-02-07
2018-02-07
Hi Dave i am trying to forward my cisco ASA logs from our Syslog server, as it is getting logs from ASA, i tried below config in my syslog.conf but i am not able to achieve it. VLC IP: 10.201.12.80ASA IP: 10.201.3.103 -------------------------------i...
View more
Likes from
User Count
Anonymous
1
PavanMishra2
PavanMishra2 Beginner
2
View all
Likes given to
User Count
DavidWaugh1
Employee DavidWaugh1
1
jeffshurtliff
Administrator jeffshurtliff Administrator
1
SravanKoneti1
SravanKoneti1 Beginner
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.