Live: Troubleshooting

Document created by RSA Information Design and Development on Oct 11, 2017Last modified by RSA Information Design and Development on Sep 12, 2018
Version 10Show Document
  • View in full screen mode

This section provides troubleshooting instructions for issues faced when using the Live Services module in NetWitness Platform.

Some Rules Are Invalid for Version 11.x

The rules "NetWitness Incident Management - Alert Details" and "NetWitness Incident Management - Incident Summary" are not valid for RSA NetWitness Platform version 11.x. Do not deploy these rules to an 11.x system.

Note: Rules are updated frequently, and the documentation for them is available in the Content space on RSA Link. For the latest information on Rules, see RSA NetWitness Rules.

Troubleshooting OutOfMemoryError on Context Hub Server

This section provide troubleshooting instructions when you encounter OutOfMemoryError on Context Hub server and the service becomes unresponsive.

If there are any TAXII feeds configured, Health and Wellness raises alerts when the available heap memory of Context Hub server is critically low. If the status of Context Hub server is Unhealthy because of low memory, perform the following:

  1. Make sure that the feeds Start Date is within 180 days.
  2. Check if any TAXII feed is consuming too much disk space. A TAXII feed can consume maximum of 300 MB. If it consumes more disk space, you must reduce the value in the Remove STIX data older than field under Advanced Options in the Custom Feed Creation Wizard when you edit a TAXII feeds.

    Note: If the issue still persists, you must execute step 3.

  1. To decrease the number of parallel threads available for processing STIX:

    1. Go to ADMIN > Services > Context Hub service > View > Explore.
    2. In the tree panel, navigate to enrichment/stix/ config.
    3. In the right panel, set the stix-query-scheduler-pool-size field value to 2. By default the value is 5. This setting controls how many number of threads are allowed to process queries for STIX data at the same time.
    4. Set the taxii-poll-scheduler-pool-size field value to 2. By default the value is 5. This setting controls how many number of threads are allowed to poll TAXII servers at the same time.
    5. Restart the Context Hub server.

Troubleshooting Content Deployment Using logon.type Meta Key

This section provides instructions for issues deploying content that uses the logon.type meta key, such as the Application Rule Nwfl_account:logon-success-direct-access.

To solve this issue, perform the following steps:

  1. In the NetWitness Platform UI, go to Configure > Live Content.
  2. In the Resource types drop-down list, select Log Device and click Search
  3. Select Envision Config file (Version 0.36 and above) from the search results.
  4. Click Deploy to deploy the content.
  5. Complete the Deployment Wizard.
You are here
Table of Contents > Troubleshooting