000026502 - How to start and stop capture or aggregation on RSA NetWitness appliance using NwConsole

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support on Sep 30, 2019
Version 4Show Document
  • View in full screen mode

Article Content

Article Number000026502
Applies ToRSA Product Set: NetWitness Logs & Network, Security Analytics
RSA Product/Service Type: Broker, Concentrator, Archiver, Log Decoder, Decoder
RSA Version/Condition: 10.6,11.0,11.1, 11.2, 11.3
Platform: CentOS 6, CentOS 7
IssueHow to start and stop capture and aggregation on RSA NetWitness appliances using NwConsole.
How can I stop and start aggregation on my concentrator, archiver, or broker appliance from the command line?
What is the method for stopping and starting capture on my decoder or log decoder device from NwConsole?
TasksNwConsole is a utility that can be used to communicate to a core service as if you were using the UI or the explore view. This is a command-line alternative to executing commands.

The following commands may be used to start and stop aggregation or capture on RSA NetWitness core appliances using NwConsole. They rely on you knowing the service level passwords for the users. These service-level users exist on the View > Security tab for each of the core services.

 Task Appliance Command
 Start Capture Decoder NwConsole -c login localhost:50004 <username> <password> -c send /decoder start
  Log Decoder NwConsole -c login localhost:50002 <username> <password> -c send /logdecoder start
 Stop Capture Decoder NwConsole -c login localhost:50004 <username> <password> -c send /decoder stop
  Log Decoder NwConsole -c login localhost:50002 <username> <password> -c send /logdecoder stop
 Start Aggregation Concentrator NwConsole -c login localhost:50005 <username> <password> -c send /concentrator start
  Broker NwConsole -c login localhost:50003 <username> <password> -c send /broker start
 ArchiverNwConsole -c login localhost:50008 <username> <password> -c send /archiver start
 Stop Aggregation Concentrator NwConsole -c login localhost:50005 <username> <password> -c send /concentrator stop
  Broker NwConsole -c login localhost:50003 <username> <password> -c send /broker stop
 ArchiverNwConsole -c login localhost:50008 <username> <password> -c send /archiver stop
 Log Collection Log Decoder NwConsole -c login localhost:50001 <username> <password> -c send /logcollection/<collection> start
 Log Collection Log Decoder

 NwConsole -c login localhost:50001 <username> <password> -c send /logcollection/<collection> stop



If you are unsure of any of the commands above or experience any issues, contact RSA Support and quote this article ID for further assistance.

Legacy Article IDa66530