To access the Discovery tab, go to NetWitness ADMIN> Event Sources. The Discovery tab is displayed.
The Discovery tab lets you review the event source types that NetWitness has discovered for each address and the system’s confidence of how likely it is that they were identified completely accurately. If the discovered event source types are correct, you can acknowledge to filter out that event source. If incorrect, you can set the allowed event source types for a particular address so that future logs will parse against the correct parsers.
Introduced in RSA NetWitness Suite version 11.1, the system automatically maps incoming events to a type based on previous logs received from that address, reducing the mis-parsing of messages and reducing the number of items that need attention in the Discovery workflow. A value of Auto in the Mapping Type column indicates that an address has been auto-mapped.
This workflow shows the overall process for configuring event sources.
*You can perform this task here.
The following example displays a list of addresses and their discovered Event Source types. The Event Source types display the Event Sources that have been discovered.
This is an example of the tab.
Displays the Filters and Event Sources panels with the Discovery tab open.
Displays the Event Source Filter field with a drop-down menu that offers the following options:
Note: When specifying the search string, you can use . - : (period, dash, colon).
|3||The Event Source Type drop-down menu filters for addresses containing all of the selected event source types.|
|6||Toggles the event sources between acknowledged and not acknowledged states.|
|7||Maps the selected event sources.|
|8||View Details button to view details of the selected Event Source.|
|9||Displays the addresses of the selected Event Sources.|
|10||Displays the discovery scores of the selected Event Sources.|
|11||Displays whether or not the selected Event Sources have been acknowledged.|
|12||Displays the selected Event Source Mapping type as Auto, Manual, or None. Any changes to the mapping are only displayed here.|
|13||Displays the host names of the Log Collectors where the Event Sources are located.|
|14||Displays the host names of the Log Decoders where the Event sources are located.|
|15||Displays the discovered Event Source Types and their associated discovery scores.|
Toolbar and Features
The Discovery tab contains the following features:
The following table describes the sorting order for discovery scores. To access the Sorting Order drop-down menu, click on the down arrow in the Event Sources column.