This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Education Courses
Announcement Banner

Users are unable to open Netwitness Support Cases via email. Please open support cases via portal or by phone

View Details
  • NetWitness Community
  • NetWitness Education
  • Courses
  • RSA NetWitness Logs & Network Troubleshooting ESA EPL Rules
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content
No ratings

RSA NetWitness Logs & Network Troubleshooting ESA EPL Rules

CraigHansen1
CraigHansen1 Beginner
Beginner
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

on ‎2016-02-04 09:48 PM

Access Training

In order to register for a class, you need to first create an EMC account

If you need further assistance, contact us

 

Summary

This on-demand learning will enable you to troubleshoot RSA NetWitness Logs & Network Event Stream Analysis (ESA) Rules.

 

Overview

This self-paced on-demand learning will improve your understanding of how to troubleshoot RSA NetWitness Logs & Network Event Stream Analysis (ESA) rules. While troubleshooting ESA in general is an important skill, the #1 issue in the field is troubleshooting ESA rules in particular. With "just show me" videos, this course addresses the most common reasons that rules don't work. It first discusses ways to determine whether or not it is a "rule issue." It outlines the most common “rule issues" and provides approaches to resolving them. The course continues with tips, tricks, and tools for troubleshooting rules and general strategies for working with rules. It also will help you avoid some common "Gotchas." The content is designed for troubleshooting the 10.x versions of the product.

 

Audience

Anyone interested in troubleshooting ESA EPL rules


Delivery Type
On-Demand Learning

 

Duration

1.5 hours

 

Prerequisite Knowledge/Skills

Students should have completed the following courses (or have equivalent knowledge) prior to taking this training:

  • RSA Troubleshooting Methodology Framework
  • RSA NetWitness Logs & Network Foundations or RSA NetWitness Logs & Network Introduction to ESA
  • RSA NetWitness Logs & Network ESA EPL Rules

 

Course Objectives

Upon successful completion of this course, participants should be able to:

  • Describe basic-practices for troubleshooting SA ESA rules
  • After viewing “just show me” style videos, identify where to go, what to look for, and a common methods for resolving common issues with ESA rules
  • Describe tips and tricks to avoid common misconfigurations

 

Course Outline

  1. Introduction
    • Narrow down ESA troubleshooting to “Rule Issues”
    • Cursory Considerations for Rule oriented issues
    • Cross-site Correlation
  2. Types of ESA Rules Issues
    • Issues Downloading Published Content
    • Missing Required Meta
    • Rules Not Able to Synchronize
    • Syntax Errors
    • Too Many Alerts
    • Memory Issues from Poorly Written Rules
    • Meta Value Case-Sensitivity
    • Time Window Issues
    • Misuse of Order and Memory
    • Problems Getting Alerts – and Storage High
    • Issues involving Too Many Events
  3. Summary
  4. Assessment
  5. Course Evaluation

 

 

 

 

Access Training

In order to register for a class, you need to first create an EMC account

If you need further assistance, contact us

  • &
  • 10.6
  • Admin
  • advanced
  • Ed Services
  • education
  • Education Services
  • elearning
  • english
  • EPL
  • epl rule
  • ESA
  • esa epl rules
  • expanding
  • learning
  • logs & network
  • navigator
  • NetWitness
  • netwitness logs & network troubleshooting esa epl rules
  • netwitness navigator
  • netwitness training
  • Network
  • NW
  • NWP
  • on demand learning
  • on-demand
  • on-demand learning
  • Product Training
  • rsa
  • RSA NetWitness
  • rsa netwitness logs & network
  • RSA NetWitness Platform
  • RSA NetWitness Training
  • RSA University
  • RSAU
  • Rules
  • training
  • Training Course
  • Troubleshooting
  • troubleshooting esa epl rules
  • university
  • write epl rules
Was this article helpful? Yes No
0 Likes
Share
Version history
Last update:
‎2016-02-04 09:48 PM
Updated by:
CraigHansen1 Beginner
Contributors
  • CraigHansen1
    CraigHansen1
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.