ESM: Discovery Tab

Document created by RSA Information Design and Development on Sep 6, 2017Last modified by RSA Information Design and Development on Oct 4, 2017
Version 8Show Document
  • View in full screen mode
  

To access this tab, in the NetWitness ADMIN> Event Sources. The Discovery tab is displayed.

The Discovery tab lets you review the event source types that NetWitness has discovered for each address and the system’s confidence of how likely it is that they were identified completely accurately. If the discovered event source types are correct, you can acknowledge to filter out that event source. If incorrect, you can set the allowed event source types for a particular address so that future logs will parse against the correct parsers.

Workflow

This workflow shows the overall process for configuring event sources.

What do you want to do?

                       
RoleI want to...Documentation
Administrator

Acknowledge that the discovered event source types are correct.

Acknowledging and Mapping Event Sources

Administrator Map the parsers that should be used for an event source when the discovered types are not completely accurate.

Acknowledging and Mapping Event Sources

Related Topics

Manage Parser Mappings

Details View

Quick Look

The following example displays a list of addresses and their discovered Event Source types. The Event Source types display the Event Sources that have been discovered.

This is an example of the tab.

                                             
1Displays the Event Source panel with the Discovery tab open.
2View Details button to view details of the selected Event Source.
3Displays the  address of the selected Event Source.
4Displays the discovery score of the selected Event Source.
5Displays whether or not the selected Event Source has been acknowledged.
6Displays whether or not the selected Event Source has been mapped to a corresponding Event Source type.
7Displays the host names of the Log Collectors where the Event Sources are located.
8Displays the host names of the Log Decoders where the Event sources are located.
9Displays the discovered Event Source Types and their associated discovery scores.
10Displays the Show Acknowledged and Show Mapped filter with options to acknowledge and map selected event sources.

Toolbar and Features

The Discovery tab contains the following features:

                                           
FieldDescription

Tools


The following item is available on the toolbar:

View Details: Provides details on the selected Event Source.

Event Source

The IP, IPv6, or Hostname of the Event Source.

Discovery Score

Displays the overall discovery score associated with that particular address. Higher scores indicate better confidence. Discovery scores range from 0 (least confident) to 100 (most confident).

Acknowledged Selections are either Yes (you have acknowledged the Event Source) or
No (you have not acknowledged the Event Source).

Mapped

Selections are either Yes (you mapped the Event Source) or
No (you have not mapped the Event Source).
Log Collector(s)

Log Collectors that have received logs from this Event Source address.

Log Decoder(s) Log Decoders that have received logs from this Event Source address.
Event Source Type(s) The parsed type(s) of the Event Source address and the corresponding Discovery Score for each type.

Note: Discovery Scores are only available for 11.0.0.0 and above Log Decoders. Discovery Scores for pre-11.0.0.0 Log Decoders display as Unavailable.

The following table describes the sorting order for discovery scores. To access the Sorting Order drop-down menu, click on the down arrow in the Event Sources column.

                       
FieldDescription

Sort Ascending

Sort the column by discovery score in ascending order.

Sort Descending

Sort the column by discovery score in descending order.

Columns

Used to hide or show one or more columns, as shown in the following example.

Example of event source sorting drop-down menu.

 

Previous Topic:ESM: Alarms Tab
You are here
Table of Contents > References > ESM: Discovery Tab

Attachments

    Outcomes