This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Knowledge Base Archive
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • NetWitness Community
  • NetWitness Knowledge Base Archive
  • Malware Analysis Audit log Max Length not working on RSA Netwitness
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content

Malware Analysis Audit log Max Length not working on RSA Netwitness

Article Number

000034495

Applies To

RSA Product Set: Netwitness for Packet
RSA Product/Service Type: Malware Analysis
RSA Version/Condition: 10.3, 10.4, 10.5, 10.6
Platform: CentOS
O/S Version: 6
 

Issue

Although Max Length(default : 2048 bytes) is set to higher value. MA audit log is truncated to a certain length.

Cause

Syslog receiver has a parameter for Max Length of the received message.

 

Resolution

Customer needs to extend the Max Length of the received message for Receiver module(eg. rsyslog). Please refer to the syslog receiver documentation.

Notes

Test to inject the same pcap twice to Netwitness.

  • 1st attempt : Set Identity String on Malware Analysis > Config page to SACE6942
  • 2nd attempt : Set Identity String on Malware Analysis > Config page to SACE6942_LONGERIDENTITY_STRING  

Regardless of the length of the Identity String, the receiver(rsyslog 5.x) truncates the message to 2K (default value for rsyslog 5.x) which is ending to the same position.

Image descriptionImage description


Reference) rsyslog
http://www.rsyslog.com/doc/v5-stable/configuration/global/index.html?highlight=maxmessagesize

$MaxMessageSize <size_nbr>, default 2k

 

Tags (33)
  • 10.4
  • 10.4.x
  • 10.5
  • 10.5.x
  • 10.6
  • 10.6.x
  • 10.x
  • Appliance
  • Core Appliance
  • Customer Support Article
  • KB Article
  • Knowledge Article
  • Knowledge Base
  • Malware
  • Malware Analysis
  • NetWitness
  • NetWitness Appliance
  • NetWitness Platform
  • NW
  • NW Appliance
  • RSA NetWitness
  • RSA NetWitness Platform
  • RSA Security Analytics
  • Security Analytics
  • SIEM
  • Version 10
  • Version 10.4
  • Version 10.4.x
  • Version 10.5
  • Version 10.5.x
  • Version 10.6
  • Version 10.6.x
  • Version 10.x
0 Likes
Was this article helpful? Yes No
Share
No ratings

In this article

Version history
Last update:
‎2020-12-13 05:55 AM
Updated by:
Administrator RSA-KB-Sync Administrator

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.