RSA NetWitness Logs and Packets decoders are responsible for the real-time collection of network data. The decode captures data in real time and can normalize and reconstruct data for full session analysis. In addition, the decoder can collect flow and endpoint data.
RSA NetWitness Packets and Logs
- Details
- Content
- Dependencies
- Version History
RSA NetWitness Logs and Packets decoders are responsible for the real-time collection of network data. The decode captures data in real time and can normalize and reconstruct data for full session analysis. In addition, the decoder can collect flow and endpoint data.
Name | Description |
---|---|
RSA NetWitness Packets and Logs |
Name | Description |
---|---|
NetwitnessSearch | Deprecated. No available replacement. Searches for matches in session/packet content |
NetwitnessQuery | Deprecated. No available replacement. Performs a query against the meta database |
Name | Description |
---|---|
RSA NetWitness Packets and Logs | RSA NetWitness Logs and Packets decoders are responsible for the real-time collection of network data. The decode captures data in real time and can normalize and reconstruct data for full session analysis. In addition, the decoder can collect flow and endpoint data. |
Name | Description |
---|---|
NetwitnessSearch | Deprecated. No available replacement. Searches for matches in session/packet content |
NetwitnessQuery | Deprecated. No available replacement. Performs a query against the meta database |
Pack Name | Pack By |
---|---|
Base | By: Cortex XSOAR |
Pack Name | Pack By |
---|
Scripts
NetwitnessSearch
- Deprecated. No available replacement.
NetwitnessQuery
- Deprecated. No available replacement.
Scripts
NetwitnessQuery
- Updated the Docker image to: demisto/python:2.7.18.24398.
NetwitnessSearch
- Updated the Docker image to: demisto/python:2.7.18.24398.
Scripts
NetwitnessQuery
- Updated the Docker image to: demisto/python:2.7.18.24066.
NetwitnessSearch
- Updated the Docker image to: demisto/python:2.7.18.24066.
Scripts
NetwitnessSearch
- Updated the Docker image to: demisto/python3:3.9.5.21272.
NetwitnessQuery
- Updated the Docker image to: demisto/python3:3.9.5.21272.
RSA NetWitness Logs and Packets decoders are responsible for the real-time collection of network data. The decode captures data in real time and can normalize and reconstruct data for full session analysis. In addition, the decoder can collect flow and endpoint data.
PUBLISHER
Cortex
PLATFORMS
INFO
Certification | Certified | Read more |
Supported By | Cortex | |
Created | December 7, 2020 | |
Last Release | February 14, 2022 |
WORKS WITH THE FOLLOWING INTEGRATIONS:
