RSA NetWitness Security Analytics
RSA Security Analytics, compatible with prior to v11. A distributed and modular system that enables highly flexible deployment architectures that scale with the needs of the organization. Security Analytics allows administrators to collect two types of data from the network infrastructure, packet data and log data.
- Category
- Analytics & SIEM
- Pack
- RsaNetwitnessSecurityAnalytics
Configuration parameters
- url — Server Url (192.168.56.101) (required)
- username — Username
- password — Password
- credentials — Username
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- proxy — Use system proxy settings
Commands (27)
- fetch-incidents — Simulates fetching incidents. Returns array of incidents from NetWitness.
- netwitness-im-add-events-to-incident — This command will add new events to existing incident.
- netwitness-im-create-incident — Creating new incident.
- netwitness-im-get-alert-details — Return single alert by id
- netwitness-im-get-alert-original — Returns the original events which this alert contains.
- netwitness-im-get-alerts — Return all the alerts filtered by filter.
- netwitness-im-get-available-assignees — Returns the available users to be assigned to incidents.
- netwitness-im-get-components — Returns all the components in the system.
- netwitness-im-get-event-details — Returns two entries. One is event details json and the second is.
- netwitness-im-get-events — Returns all the events in defined time range.
- netwitness-im-get-incident-details — Returns incident json by id.
- netwitness-im-list-incidents — Fetches incidents by filter.
- netwitness-im-login — Logins to the system and returns valid sessionId.
- netwitness-im-update-incident — Updates incident.
- nw-add-events-to-incident — This command will add new events to existing incident.
- nw-create-incident — Creating new incident.
- nw-get-alert-details — Return single alert by id
- nw-get-alert-original — Returns the original events which this alert contains.
- nw-get-alerts — Return all the alerts filtered by filter.
- nw-get-available-assignees — Returns the available users to be assigned to incidents.
- nw-get-components — Returns all the components in the system.
- nw-get-event-details — Returns two entries. One is event details json and the second is event/session content.
- nw-get-events — Returns all the events in defined time range.
- nw-get-incident-details — Returns incident json by id.
- nw-list-incidents — Fetches incidents by filter.
- nw-login — Logins to the system and returns valid sessionId.
- nw-update-incident — Updates incident.