RSA NetWitness Packets and Logs
RSA NetWitness Logs and Packets decoders are responsible for the real-time collection of network data. The decode captures data in real time and can normalize and reconstruct data for full session analysis. In addition, the decoder can collect flow and endpoint data.
- Category
- Analytics & SIEM
- Pack
- RsaNetWitnessPacketsAndLogs
Configuration parameters
- url — Server URL (e.g. http(s)://192.168.0.1) (required)
- port — Appliance Port - Logs(50102) / Packets(50104) / Concentrator (50105) / Broker (50103) (required)
- username — Username
- password — Password
- user_creds — Username
- secure — Validate server certificate
- proxy — Use system proxy settings
- expiry — Expiration time
Commands (9)
- netwitness-msearch — Search for pattern matches in many sessions or packets
- netwitness-packets — Stream packets back based on the input parameters provided
- netwitness-query — Performs a query against the meta database
- netwitness-search — Searches for matches in session/packet content
- nw-database-dump — Dumps information out of the database in nwd formatted files
- nw-sdk-content — Returns the packet content for a session
- nw-sdk-session — Retrieves the meta id range for the session range
- nw-sdk-summary — Retrieves summary information from the databases
- nw-sdk-values — Performs a value count query and returns the matching values for a report