Skip navigation
All Places > Products > RSA NetWitness Platform > RSA NetWitness Platform Online Documentation > Documents
Log in to create and rate content, and to follow, bookmark, and share content with other members.

Investigate: Events View - Text Tab

Document created by RSA Information Design and Development Employee on Sep 18, 2017Last modified by RSA Information Design and Development Employee on Oct 16, 2020
Version 20Show Document
  • View in full screen mode
 

The Text tab is in the Event Details panel. Here you can safely view and analyze the raw text payload of an event. The Text reconstruction includes features that can show decompressed or compressed text, expand truncated entries, perform URL and Base64 encoding and decoding, and download network events, logs, and endpoint events. The text reconstruction is available for all types of events: network, log, and endpoint.

Workflow

high-level workflow with Packet tab tasks highlighted

What do you want to do?

                                                               
User RoleI want to ...Show me how

Incident Responder or Threat Hunter

review detections and signals seen in my environment

NetWitness Platform Getting Started Guide

Incident Responder

review critical incidents or alerts

NetWitness Respond User Guide

Threat Hunterquery a service, metadata, and time range

Begin an Investigation in the Events View

Begin an Investigation in the Navigate or Legacy Events View

Threat Hunter

view metadata*

Filter Results in the Navigate View

Drill into Metadata in the Events View (BETA)

Threat Hunter

view sequential events*

Filter Results in the Events View

Filter Results in the Legacy Events View

Threat Hunter

reconstruct and analyze an event*

Examine Event Details in the Events View

Reconstruct an Event in the Legacy Events View

Threat Hunterexamine files and associated hosts*

Download Data in the Events View

Export or Print a Drill Point in the Navigate View

Export Events in the Legacy Events View

Threat Hunterperform lookups*

Look Up Additional Context for Results

Launch a Lookup of a Meta Key

Threat Huntercreate an incident or add to an incident

Add Events to an Incident in the Legacy Events View

Add Events to an Incident in the Events View

Threat Hunter

add a meta value to a Context Hub list*

Look Up Additional Context for Results

*You can perform this task in the current view.

Related Topics

Quick Look

The Events view displays the text of a single event in the Text panel (formerly known as Text Analysis). When you click an event in the Event list panel, the adjacent panel shows the text reconstruction. Only the raw log for log events and endpoint events is shown in the Text panel. For network events, the direction of the packet (Request or Response) and contents of each packet are provided in text format. For more examples of the Text, see Reconstructing and Analyzing Events. For detailed procedures, see Analyze Events in the Events View.

Text Analysis with important features labeled

                         
1Options for exporting a log, a PCAP, or files for deeper analysis and to share with others. This download menu is for network data.
2The event header information.
3The payload for a network event includes requests and responses. This is the request side of the packet.
4This is the response side of the packet.
5

(Version 11.2 and later) Event pagination controls allow more flexibility in paging through a list of events. When a control is unavailable, the image is dimmed; for example, when you are viewing page 1, the the pagination button to go to page 1 and the pagination button to go to the previous page controls are dimmed.

the pagination button to go to page 1 - Go to the first page

the pagination button to go to the previous page - Go to the previous page

the pagination button to go to the next page - Go to the next page

the pagination button to go to the last page - Go to last page (Only available after last page has already been navigated to)

You are here
Table of Contents > Investigate Reference Materials > Events View - Text Tab

Attachments

    Outcomes