Decoder: Upload a Log File to a Log Decoder

Document created by RSA Information Design and Development on Sep 13, 2017Last modified by RSA Information Design and Development on Oct 11, 2017
Version 6Show Document
  • View in full screen mode
 

This topic describes the method for importing a log file to a Log Decoder.

There are occasions when you want to analyze a log file that is not available on the service you are using. You can upload a log file captured on another service to NetWitness Suite. Log filenames are of the type .log.

When a log file is uploaded to a Log Decoder, the Log Decoder analyzes and generates meta for each log it contains. These logs are added to the already decoded logs on the Log Decoder and are available for analysis. NetWitness Suite includes a filename tracking option that makes searching for a particular set of logs easier. When the log file is uploaded with file tracking, the Log Decoder adds meta to each log based on the uploaded filename. You can then filter sessions for analysis using that meta.

The option to upload a log file is dimmed when other Log Decoder operations prevent an upload from occurring. For example, when the Log Decoder is capturing logs. 

To import a log file to an Log Decoder:

  1. Go to ADMIN > Services.
  2. Select a Log Decoder in the Service grid, and select  Actions menu  > View > System.
    The Services System view for the Log Decoder is displayed.
  3. In the toolbar, click Upload Log File.
    This is the Upload Log File dialog.
  4. To choose a log file, click Browse.
    A directory view is displayed.
  5. Select the log file that you want to upload.
    The filename is displayed in the Upload File field.
  6. If you want the Log Decoder to add meta to the logs based on the filename, click the checkbox next to Track Filename.
  7. To upload the file, click Upload.
    The selected file is uploaded and a status message indicates that the file is uploaded. The log file is available for analysis.
You are here
Table of Contents > Decoder and Log Decoder Additional Procedures > Upload a Log File to a Log Decoder

Attachments

    Outcomes