Acknowledge Event Source Types
The Discovery tab lets you review the event source types that NetWitness has discovered for each address and the system’s confidence of how likely it is that they were identified accurately. If the discovered event source types are correct, you can acknowledge to filter out that event source from the view by default. If incorrect, you can set the allowed event source types for a particular address so that future logs will parse against the correct parsers.
To acknowledge that the discovered event source types are correct, do the following
- Select the Event Sources that you want to Acknowledge and click the Acknowledge button in the toolbar. Once the Event Sources are Acknowledged, they are no longer displayed in the Event Source Type(s) column.
Map Event Source Types
When discovered event source types are not completely accurate, you can map the parsers to obtain additional information by doing the following:
- Select the Event Sources that you want to Map and click the Map button in the toolbar.