000031109 - How to view custom feed contents that are deployed to an RSA Security Analytics Log Decoder

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support Employee on Apr 21, 2017
Version 4Show Document
  • View in full screen mode

Article Content

Article Number000031109
Applies ToRSA Product Set: Security Analytics
RSA Product/Service Type: Log Decoder, Security Analytics UI
RSA Version/Condition:
IssueThere is no way to see the contents of a deployed custom feed via the Security Analytics UI.
ResolutionThe contents of a custom feed can be viewed via the shell console on the Log Decoder appliance, following the steps below.
  1. Connect to the Log Decoder via SSH as the root user.
  2. Navigate to the directory where the feeds are stored.
    cd /etc/netwitness/ng/feeds/

  3. Use the NwConsole utility to dump the custom feed contents.
    Note: Each time output file name should be different when running NwConsole command.
    NwConsole -c feed dump <feed_file_name> <output_file_name>

  4. Use the cat command to display the contents of the feed.
    User-added image
If you are unsure of any of the steps above or experience any issues, contact RSA Support and quote this article number for further assistance.