000026806 - How to perform a data reset on an RSA NetWitness decoder

Document created by RSA Customer Support Employee on Jan 12, 2017Last modified by RSA Customer Support Employee on Apr 21, 2017
Version 2Show Document
  • View in full screen mode

Article Content

Article Number000026806
Applies ToRSA NetWitness NextGen
RSA NetWitness Decoder
RSA NetWitness Log Decoder
RSA NetWitness Hybrid
IssueHow to perform a data reset on an RSA NetWitness decoder.
Resolution

It may be necessary to perform a data reset on a decoder for any number of reasons including:


  • Corruption on databases (in addition to the Index, which can easily be reset itself without data reset)
  • Removing all data on the device

Follow these steps in NetWitness Administrator to perform a data reset on a Decoder:


  1. On the Decoder, stop Capture by clicking the "Stop Capture" icon in the "Stats" view.
  2. Open the "Logs" view and wait for the "Capture has stopped" message. It may take some time so please be patient.
  3. On the upstream Concentrator, remove the Decoder on the Concentrator's "Stats" view by finding the Decoder, clicking it's drop-down menu and selecting "Remove device."
  4. Back on the Decoder, open the "Console" view and type "/decoder reset data=1" in the command line and click send.
  5. This will cause all databases to be zeroed and the Decoder service will be restarted automatically.  If there is a lot of data on the Decoder it may be a minute or two while the system deletes the database files.
  6. Once you can connect back to the Decoder using Administrator, you can also add the Decoder back into an upstream Concentrator.
NotesCaveat:

If for any reason, you are unable to do a data reset via RSA NetWitness Administrator, there is an alternate solution called a "Manual Data Reset" which is detailed in the knowledgebase article How to perform a manual data or index reset on an RSA NetWitness appliance.

Legacy Article IDa58729

Attachments

    Outcomes