This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Knowledge Base Archive
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcement Banner

Users are unable to open Netwitness Support Cases via email. Please open support cases via portal or by phone

View Details
  • NetWitness Community
  • NetWitness Knowledge Base Archive
  • event.time meta displays old time in Windows Legacy Collection(WLC)
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content

event.time meta displays old time in Windows Legacy Collection(WLC)

Article Number

000039804

Applies To

RSA Product Set: RSA NetWitness Platform
RSA Product/Service Type: Security Analytics Server
RSA Version/Condition: 11.5.x
Platform: CentOS
O/S Version: 7

Issue

When querying data from Windows Legacy Collection(WLC) via Investigate, event.time meta displays old time as you can see below.


And you can also see "View Meta" below, event.time meta shows 2015-07-20 date while time meta displays 2021-04-23 date.


From the event viewer properties for the security event log, it was observed that the file has a max size of 16 MB, but the actual log file size observed was more than 2 GB. 
This implies that the customer had set a much larger max size and changed it to a smaller value. 
Windows do not auto shrink this file, and it will only do that if the event log is cleared. 
Since the windows API field for the record id of WLC is 4 bytes in size then the max the API can handle is 4 billion so it is most likely overflowing to a smaller number (maybe 0 which is invalid) so WCL actually reads older events.

Resolution

The solution is that you need to shrink the actual log file size by clearing the event log and then ensure record id numbering can be restarted in windows machine.
Tags (47)
  • 11.3
  • 11.3.x
  • 11.4
  • 11.4.x
  • 11.5
  • 11.5.x
  • 11.x
  • API
  • API Help
  • API Issue
  • API Issues
  • API Problem
  • Appliance
  • Break Fix
  • Break Fix Issue
  • Broken
  • Core Appliance
  • Customer Support Article
  • Issue
  • Issues
  • KB Article
  • Knowledge Article
  • Knowledge Base
  • Log Collection
  • Log Collector
  • NetWitness
  • NetWitness Appliance
  • NetWitness Platform
  • NW
  • NW Appliance
  • NwLogCollector
  • Problem
  • Product API
  • REST API
  • RSA NetWitness
  • RSA NetWitness Platform
  • RSA Security Analytics
  • Security Analytics
  • SIEM
  • Version 11
  • Version 11.3
  • Version 11.3.x
  • Version 11.4
  • Version 11.4.x
  • Version 11.5
  • Version 11.5.x
  • Version 11.x
0 Likes
Was this article helpful? Yes No
Share
No ratings

In this article

Version history
Last update:
‎2021-07-26 01:26 PM
Updated by:
Administrator RSA-KB-Sync Administrator

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.