Skip to main content

RSA NetWitness Packets and Logs

Download With Dependencies

RSA NetWitness Logs and Packets decoders are responsible for the real-time collection of network data. The decode captures data in real time and can normalize and reconstruct data for full session analysis. In addition, the decoder can collect flow and endpoint data.

RSA NetWitness Packets and Logs provides visibility of data related to packets and logs residing on Netwitness. The pack can provide crucial information by filtering through logs/packets on Netwitness and provide analysts with insights to potential threats.

What does this pack do?

  • Filter logs/packets based on sessions.
  • Stream packets based on sessions.
  • Perform value count query basd on field names.
  • Retrieve meta values for multiple sessions.
  • Filter logs and packets based on pattern matches.

Note: Support for this Pack moved to the partner on 04, 21, 2024.

Please contact the partner directly via the support link on the right.

RSA NetWitness Packets and Logs provides visibility of data related to packets and logs residing on Netwitness. The pack can provide crucial information by filtering through logs/packets on Netwitness and provide analysts with insights to potential threats.

What does this pack do?

  • Filter logs/packets based on sessions.
  • Stream packets based on sessions.
  • Perform value count query basd on field names.
  • Retrieve meta values for multiple sessions.
  • Filter logs and packets based on pattern matches.

Note: Support for this Pack moved to the partner on 04, 21, 2024.

Please contact the partner directly via the support link on the right.

PUBLISHER

PLATFORMS

Cortex XSOARCortex XSIAM

INFO

CertificationRead more
Supported ByCortex
CreatedDecember 7, 2020
Last ReleaseMay 8, 2024
WORKS WITH THE FOLLOWING INTEGRATIONS:

DISCLAIMER
Content packs are licensed by the Publisher identified above and subject to the Publisher’s own licensing terms. Palo Alto Networks is not liable for and does not warrant or support any content pack produced by a third-party Publisher, whether or not such packs are designated as “Palo Alto Networks-certified” or otherwise. For more information, see the Marketplace documentation.