000031109 - How to view custom feed contents that are deployed to an RSA Security Analytics Log Decoder

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support on Dec 20, 2019
Version 5Show Document
  • View in full screen mode

Article Content

Article Number000031109
Applies ToRSA Product Set: Security Analytics
RSA Product/Service Type: Log Decoder, Security Analytics UI
RSA Version/Condition: 11.X
IssueThere is no way to see the contents of a deployed custom feed using the Security Analytics UI.
ResolutionThe contents of a custom feed can be viewed using the shell console on the Log Decoder appliance, following the steps below.
  1. Connect to the Log Decoder using SSH as the root user.
  2. Go to the directory where the feeds are stored.

    cd /etc/netwitness/ng/feeds/

  3. Use the NwConsole utility to dump the custom feed contents.
    Note: Each time output file name should be different when running NwConsole command.

    NwConsole -c feed dump <feed_file_name> <output_file_name>

  4. Use the cat command to display the contents of the feed.
    User-added image
  To view meta keys involved in custom feeds, follow the below steps.

  1. Go to feeds directory using cd /etc/netwitness/ng/feeds
  2. Run NwConsole -c feed stats <feedname> to view meta key details for this feed.


[root@Dec feeds]# NwConsole -c feed stats FINUsersFeedSrc.feed
RSA NetWitness NextGen Console
Copyright 2001-2018, RSA Security Inc.  All Rights Reserved.

>feed stats MyUsersFeedSrc.feed
FINUsersFeedSrc stats:
        version     : 0
        keys count  : 1
        values count: 1
        record count: 205
        meta key    : user.src
        language keys:
                user_group_src  Text

More details on this command see NwConsole Useful Commands

If you are unsure of any of the steps above or experience any issues, contact RSA Support and quote this article number for further assistance.