Archer Integ: Troubleshoot RSA Archer Integration

Document created by RSA Information Design and Development on Oct 11, 2017Last modified by Shree Kulkarni on Nov 23, 2018
Version 13Show Document
  • View in full screen mode

This section provides resolutions to common problems that you may encounter while configuring RSA Archer® Cyber Incident & Breach Response with NetWitness Respond. 

Unable to add NetWitness Endpoint successfully to UCF. Login to the NetWitness server console and check the truststore.pem file under /etc/rabbitmq/ssl/truststore.pem and verify if the certificates (rootcastore.crt.pem and keystore.crt.pem) are updated correctly. If the certificates are not updated, manually copy the contents of both the certificates to the truststore.pem file. After updating, restart the rabbitmq service.

After adding the endpoint for NetWitness Respond, the Certificate Authority truststore fails to set.


  1. Make sure that the SSH credentials for the NetWitness Platform host are valid.
  2. If the credentials are correct, but the error still occurs, manually copy certificates.
Remediation Tasks being pushed to the operations queue through the UCF are not appearing in RSA Archer® Cyber Incident & Breach Response as Findings. 
  1. Open the Connection Manager using the command prompt:
    • Change directories to <install_dir>\SA IM integration service\data-collector.
    • Type: runConnectionManager.bat
  1. Enter 2 to edit endpoint.
  2. Enter 3 to NetWitness Platform Respond.
  3. Make sure the Target Queue is set to All or Operations.
In the <install_dir>\SA IM integration service\logs\collector.log, there are SSL errors between RSA NetWitness Platform and RSA Unified Collector Framework.
    1. Verify that the SSL certificates are valid.

Note: NetWitness Respond certificates are valid for two years. 

    1. If your certificates are expired, regenerate and copy the expired certificates.

To regenerate and copy the certificates:

      1. In the Command Prompt, go to <install_dir>\SA IM integration service\data-collector.
      2. Enter runConnectionManager.bat
      3. Enter the number for Regenerate NetWitness Platform RESPONDIntegration Service Certificate.

      4. In the NetWitness Platform Respond endpoint, in Connection Manager, enter the number for Edit Endpoint.
      5. Enter Yes to copy the certificates automatically to the NetWitness Platform trust store.

Note: If certificates fail to copy, manually copy the certificates.

When ESA alerts with severity High or Low are forwarded to RSA Archer, the Security Alert Priority field is not populated in the RSA Archer UI.None, as it functions as designed.
When ESA Command and Control Aggregate Scores details are forwarded from NetWitness Suite to RSA Archer UI, fields such as Beaconing Behavior, Rare Domains, Rare User Agents, Missing Referrers, and Suspicious Domains Aggregate Score do not get populated.None, as it functions as designed.
RSA Archer recurring feeds does not work in SSL mode.Make sure you create the RSA Archer recurring feeds in non-SSL mode.


You are here

Table of Contents > Troubleshoot RSA Archer Integration