This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Knowledge Base Archive
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcement Banner

Users are unable to open Netwitness Support Cases via email. Please open support cases via portal or by phone

View Details
  • NetWitness Community
  • NetWitness Knowledge Base Archive
  • "# EVENTS" column in RESPOND > Alerts displays up to 100 counts in RSA NetWitness Platform
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content

"# EVENTS" column in RESPOND > Alerts displays up to 100 counts in RSA NetWitness Platform

Article Number

000039567

Applies To

RSA Product Set: RSA NetWitness Platform
RSA Product/Service Type: Core Appliance
RSA Version/Condition: 11.3.2.0
Platform: CentOS
O/S Version: 6

Issue

When you look at "# EVENTS" column in RESPOND > Alerts, it shows up to 100 counts as shown below.
Image descriptionImage description

Here is an example via the "Web Dos Alerts" ESA rule.
Refer to the following screenshot of ESA syntax. 
Image descriptionImage description
Case 1) If HAVING COUNT(ip_dst) >= 150 inside ESA rule syntax, "# Event" column shows 100 based on first screenshot.
Case 2) If HAVING COUNT(ip_dst) <= 100 inside ESA rule syntax, "# Event" column changed to 40 based on first screenshot.

Resolution

Events counts in the Respond > Alerts always show 100 because the default value of 'max-constituent-events' for the ESA rule is set to 100 for better performance. 
Due to this reason, only 100 events are shown in UI.

You can increase this value with the following steps.
  1. Go to Admin->Services->ESA->Explore->correlation->rule
  2. Under the field, 'max-constituent-events' changes the value from 100 to 200 as per your requirement. 
With this change, you are able to see all the 150 Events in Respond > Alerts page in this case.
 
Tags (46)
  • 11.x
  • Alert
  • Alerting
  • Alerts
  • Appliance
  • Break Fix
  • Break Fix Issue
  • Broken
  • Config
  • Configuration
  • Configuration Help
  • Configuration Issue
  • Configuration Problem
  • Configuring Issue
  • Configuring Problem
  • Customer Support Article
  • ESA
  • ESA Appliance
  • ESA Service
  • Event Stream Analysis
  • IM
  • Incident Alert
  • Incident Management
  • Incident Manager
  • Issue
  • Issue Configuring
  • Issues
  • KB Article
  • Knowledge Article
  • Knowledge Base
  • NetWitness
  • NetWitness Appliance
  • NetWitness Platform
  • NW
  • NW Appliance
  • Problem
  • RSA NetWitness
  • RSA NetWitness Platform
  • RSA Security Analytics
  • Security Analytics
  • Setup Issue
  • SIEM
  • UI
  • User Interface
  • Version 11
  • Version 11.x
0 Likes
Was this article helpful? Yes No
Share
No ratings

In this article

Version history
Last update:
‎2021-04-24 04:35 AM
Updated by:
Administrator RSA-KB-Sync Administrator

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.