|Applies To||RSA Product Set: NetWitness Platform|
RSA Product/Service Type: NetWitness Core services
RSA Version/Condition: 10.6.x, 11.x
|Issue||How to add custom meta keys in RSA NetWitness?|
What is the process of adding custom language keys in RSA NetWitness?
After adding custom meta keys in my concentrators, I can see the custom meta keys show up when Investigating directly using the concentrators, but why is the broker rendering errors in Investigations such as below:
|Tasks||In RSA NetWitness, the default configuration of meta keys is stored in the index-<service>.xml files (for example, index-concentrator.xml) on the NetWitness appliances.|
The contents of these default files should not be manually changed as a new version of these files may be deployed during version upgrades.
Beginning from RSA NetWitness 10.0 a custom XML file, index-<service>-custom.xml (for example, index-concentrator-custom.xml) can be created in the same directory as the default file.
The custom XML file will not be modified or overwritten during a version upgrades.
Customization changes of the default settings, or adding new custom meta keys should be added to the custom XML file.
Add the custom meta key lines or meta key modifications only to the index-concentrator-custom.xml file. No need to edit or add on the index-<other services>-custom.xml files.
The broker does not have their own index nor database, it only gets its unified index keys from the concentrators and/or brokers below it.
To ensure that the broker gets a unified index (language keys), edit (using the UI) and push the modified index-concentrator-custom.xml file to all the rest of the concentrators. Restart the concentrator services or initiate an index save on each (using concentrator>view>explore>index right-click-properties, select save in the drop-down and send) for the service to pick up the modified index language keys.
It is important for all concentrators to have a single uniform index-concentrator-custom.xml file so it will have a unified language definition that will in turn be picked up the broker.
There are times that you may also need to do an index reset on the broker to have it pick up immediately the new index language keys from its concentrators.
To initiate an index reset on the broker, go to Services>broker>view>explore>broker right-click-properties, select reset in the drop-down, enter index=1 in the Parameters and send.
|Resolution||How to add custom meta keys in RSA NetWitness Platform|
Changes to default meta keys' configuration and the addition of new custom meta keys is made to the custom XML file, index-<service>-custom.xml which will be in the /var/netwitness/ng directory.
Decoder service has index-decoder-custom.xml
Log Decoder service has index-logdecoder-custom.xml
Concentrator service has index-concentrator-custom.xml
|Legacy Article ID||a63114|