Feeds and parsers are Lua programs loaded and compiled when either processing capture files in NetWitness Investigate or capturing data with Decoders. Most commonly, they are used for static meta extraction and service identification.
Note: Pre-11.0 versions of NetWitness used FLEXPARSE programs in addition to Lua programs; Flexparsers are deprecated in NetWitness Platform 11.0. Unless otherwise stated, any reference to Decoders applies to Log Decoders as well.
NetWitness Platform uses feeds to create metadata based on externally defined meta values. A feed is a list of data that is compared to sessions as they are captured or processed. For each match, additional metadata is created. This data can identify and classify malicious IPs or incorporate additional information such as department and location based on internal network assignments. Some examples of feeds include threat feeds to identify BOTNets, DHCP mappings, or even active directory information such as physical location or logical department.
Feeds can be added, removed, and updated while a Decoder is running without affecting capture. The Feeds tab ( (Admin) > Services > select a Decoder or Log Decoder service and click > View > Config > Feeds tab) provides a user interface for managing feeds on Decoders.
What do you want to do?
|User Role||I want to...||Documentation|
|Administrator||configure feeds||Configure Parsers and Feeds|
|Administrator||enable and disable parsers||Enable and Disable Parsers and Log Parsers|
This is an example of the Feeds tab.
|1||Feeds Tab Toolbar - Provides options to work with feeds in the grid|
|2||Feed List - Lists all feeds that are currently deployed on the Decoder|
Feeds Tab Toolbar
The Feeds list provides a listing of all currently deployed feeds for the Decoder.
|Name||The name of the feed or the feed file.|
|Live||Indicates if the feed originated from Live. Possible values are Yes, No, or N/A. |
|Date Installed||The date the feed was pushed to the service.|