Viewing Logs from Pre-11.0.0.0 Log Decoder

Document created by RSA Information Design and Development on Sep 6, 2017Last modified by RSA Information Design and Development on Oct 4, 2017
Version 8Show Document
  • View in full screen mode
  

NetWitness 11.0.0.0 added the capability to view a small sampling of recent logs for specific devices through detail tabs of the Discovery View. By default, Log Decoders prior to 11.0.0.0 do not have the necessary configuration to enable this feature, but a few minor changes can make it available.

To enable logs preview for a pre-11.0.0.0 Log Decoder, follow these steps on the Log Decoder:

  1. Go to ADMIN > Services > select a Log Decoder, then select > View > Config.
  2. Click Files tab, then select index-logdecoder-custom.xml from the drop-down menu.
  3. Add the following three lines at the end of the file (before the closing language tag):

<key description="Device IP" level="IndexValues" name="device.ip" format="IPv4" valueMax="100000" defaultAction="Open"/>

<key description="Device IPv6" level="IndexValues" name="device.ipv6" format="IPv6" valueMax="100000" defaultAction="Open"/>

<key description="Device Host" level="IndexValues" name="device.host" format="Text" valueMax="100000" defaultAction="Open"/>

  1. Click Apply.
    Example of index-logdecoder-custom.xml file.
  2. Restart the Log Decoder as follows.
    Select Log Decoder > Explore > sys > Properties > shutdown

This is an example of the index-logdecoder-custom.xml file.

Note: Discovery Scores are only available for 11.0.0.0 and above Log Decoders. Discovery Scores for pre-11.0.0.0 Log Decoders display as Unavailable.

The following example displays the Discovery Score as Unavailable in the Details view for a pre-11.0.0.0 Log Decoder.

Example shows that a pre-11.0 Log Decoder is listed as Unavailable.

Note: Device logs are only available for 11.0.0.0 and above Log Decoders.

The following example shows the message that displays in the displays in the Logs panel for a pre-11.0.0.0 Log Decoder.

Example of message that displays when a pre-11.0 Log Decoder is discovered.

You are here
Table of Contents > Manage Event Source Groups > ESM: Viewing Logs from Pre-11.0.0.0 Log Decoder

Attachments

    Outcomes