This section provides troubleshooting instructions for issues faced when using the Live Services module in NetWitness Platform.
The rules "NetWitness Incident Management - Alert Details" and "NetWitness Incident Management - Incident Summary" are not valid for RSA NetWitness Platform version 11.x. Do not deploy these rules to an 11.x system.
Troubleshooting OutOfMemoryError on Context Hub Server
This section provide troubleshooting instructions when you encounter OutOfMemoryError on Context Hub server and the service becomes unresponsive.
If there are any TAXII feeds configured, Health and Wellness raises alerts when the available heap memory of Context Hub server is critically low. If the status of Context Hub server is Unhealthy because of low memory, perform the following:
- Make sure that the feeds Start Date is within 180 days.
Check if any TAXII feed is consuming too much disk space. A TAXII feed can consume maximum of 300 MB. If it consumes more disk space, you must reduce the value in the Remove STIX data older than field under Advanced Options in the Custom Feed Creation Wizard when you edit a TAXII feeds.
To decrease the number of parallel threads available for processing STIX:
- Go to ADMIN > Services > Context Hub service > View > Explore.
- In the tree panel, navigate to enrichment/stix/ config.
- In the right panel, set the stix-query-scheduler-pool-size field value to 2. By default the value is 5. This setting controls how many number of threads are allowed to process queries for STIX data at the same time.
- Set the taxii-poll-scheduler-pool-size field value to 2. By default the value is 5. This setting controls how many number of threads are allowed to poll TAXII servers at the same time.
- Restart the Context Hub server.
Troubleshooting Content Deployment Using logon.type Meta Key
This section provides instructions for issues deploying content that uses the logon.type meta key, such as the Application Rule Nwfl_account:logon-success-direct-access.
To solve this issue, perform the following steps:
- In the NetWitness Platform UI, go to Configure > Live Content.
- In the Resource types drop-down list, select Log Device and click Search
- Select Envision Config file (Version 0.36 and above) from the search results.
- Click Deploy to deploy the content.
- Complete the Deployment Wizard.