Investigate: Troubleshooting Investigate

Document created by RSA Information Design and Development on Mar 27, 2018Last modified by RSA Information Design and Development on Sep 11, 2018
Version 4Show Document
  • View in full screen mode

This section provides information about possible issues when using NetWitness Investigate.

Navigate View and Events View Issues

MessageNot indexed; will experience longer than usual load times. in the Manage Meta Groups dialog.

Meta keys in the Manage Meta Groups dialog are marked by a red exclamation point, and the error message is displayed. This can occur when investigating a Broker or Decoder and adding a meta group with meta keys that are not indexed in the index file or the custom index file for the service.

For a Broker, it could mean that the Broker has not begun aggregating data from a Concentrator. In this case the Broker will not have the contents of the custom index file from the aggregate services and the keys will not be indexed.

For a Decoder, it means that the meta keys are not indexed in the Decoder index or custom index file.


To fix the issue on a Broker, log out, log in, and restart the Broker service so that it can aggregate the meta key information from connected Concentrators. To fix the issue on a Decoder, edit the custom index file to index the meta keys, log out, log in, and restart the Decoder service.



When downloaded from the Event Reconstruction view, logs and metadata are always in text format irrespective of the format selected in the Events view.


When you download metadata or a log in the Event Reconstruction view, the format that you selected in the Events view is not used. The exported data is always in text format.


Download metadata and logs from the Events view if you want to use a format other than text format.

Event Analysis View Issues

BehaviorThe query builder in Version 11.2 includes Next Gen Mode, an undocumented beta feature.
IssueVersion 11.2 included an undocumented beta feature, called Next Gen mode, in the Event Analysis view query builder that was still being developed and tested. Next Gen mode was disabled in the patch.

If you see Next Gen mode do not use it; you should use only the Guided Mode and Free-Form Mode in the query builder to ensure consistent and predictable results.
Next Gen Mode


MessageInvestigation Profiles/OOTB column groups are not present in Event Analysis
IssuePost upgrade to RSA NetWitness v11.1, the default column groups - Endpoint Analysis, Outbound SSL and Outbound Http are not added under column groups. Also, a few of the Investigation Profiles are missing post upgrade.

It is observed that this issue occurs only when you have created a custom column group with the name which is same as one of the new 11.1 OOTB custom column group name. For example, if you create a custom column group in 11.0 with name RSA Endpoint Analysis then after upgrade to 11.1. Due to the same name already existing in 11.1, OOTB column groups and OOTB profiles will not be available in the UI.

To fix this, change the name of custom column group to something else and restart the jetty server using the following command on the NetWitness server:

systemctl restart jetty


MessageApplicable for hosts with 4.x Endpoint agents installed, please install the NetWitness Endpoint Thick Client.
IssueWhen you click Pivot to Endpoint in the Event Analysis view, no data is displayed and the message is displayed.
ExplanationVersion 4.4 of the NetWitness Endpoint Thick Client must be installed on the same server, the NWE meta keys must exist in the table-map.xml file on the Log Decoder, and the NWE meta keys must exist in the index-concentrator-custom.xml file. The NWE Thick Client is a Windows only application. Complete setup instructions are provided in the NetWitness Endpoint User Guide for Version 4.4.


MessageEvent Analysis requires all core services to be NetWitness 11.1. Connecting prior versions of services to the 11.1 NetWitness Server results in limited functionality (see "Investigate in Mixed Mode" in the Physical Host Upgrade Guide).
IssueWhen attempting to investigate a service that has not been updated to Version 11.1 in the Event Analysis view, the informational message is displayed.
ExplanationWhen an analyst opens the Event Analysis view in mixed mode (that is, some services are upgraded to 11.1 and some are still on 11.0.0.x or 10.6.x), Role-Based Access (RBAC) is not applied uniformly. This affects viewing and downloading content, and validation of filters in the interactive breadcrumb. You will see this informational message when you open Event Analysis. As you select a service, services that are not up to date are displayed in a red box, with the message that the service is not up to date. When your administrator has upgraded all connected services to 11.1, these features work as expected.


MessageForbidden. You cannot access the requested page.
IssueWhen attempting to access the Event Analysis view, the view opens with the message.
ExplanationYour administrator has prevented access to the Event Analysis view using role and permissions.



Insufficient permissions for the requested data.

IssueWhile attempting to access an event in Event Analysis by any means, the reconstruction is not displayed and the message is displayed.
ExplanationYou have entered an event ID for an event that you do not have permission to view. The administrator may have placed some restrictions to limit access by role and permissions.


MessageInvalid session ID: <<eventId>>
IssueNo sessionId matches the sessionId that you queried.
ExplanationThe reason for an invalid session ID can vary. Perhaps you edited the session ID manually, and no such session exists. Another case may be when you query a Broker, and the aggregated data has not been refreshed, you may see this error for a session that no longer exists.


MessageNo text data was generated during content reconstruction. This could mean that the event data was corrupt/invalid, or that an administrator has disabled the transmission of raw endpoint events in the Endpoint server configuration. Check the other reconstruction views.
IssueWhen you reconstruct an event as text in the Event Analysis view, no data is displayed and the message is displayed.
ExplanationIf you do not see the raw text in other Event Analysis views or Events view reconstructions, and you believe the data is not corrupted or invalid, your administrator has likely disabled transmission of raw endpoint events on the NetWitness Endpoint server. Contact your administrator for additional information.



Session is unavailable for viewing.

IssueWhile querying an event ID, the reconstruction is not displayed and the message is displayed.
ExplanationThe query you entered is trying to look at restricted data, for example, if you are allowed to see only log data and you are using a link to network data that you were allowed to see yesterday.


MessageThe session id is too large to be handled:<<eventId>
IssueThe sessionId integer that you typed in, edited, or got from the Events view or Navigate view is too large.
ExplanationIf you manually typed the sessionId or edited a sessionId in the Event Analysis view, you may have created an integer that is too large for Event Analysis to process.



While creating a filter in the Event Analysis view, you cannot enter a complex expression using the AND or OR operator in Query Builder.

IssueThe query builder in the Event Analysis view supports only simple expressions in the form <meta key><operator><meta value>.

If you want to enter a filter that uses the AND or OR operator, you need to enter the query it from the Navigate view or Events view and then open it in the Event Analysis view. You can enter some complex expressions as two separate filters in the Event Analysis view. The filters will be AND'd when you execute the query.

Hosts View Issues

MessageAn error has occurred. The Endpoint Server may be offline or inaccessible.
IssueWhen attempting to access the Hosts or Files view, the view opens with the message.

Endpoint Server or Nginx Server is not running. Check the status of the Endpoint Server under Admin > Service or check if the Endpoint Server host IP address is registered with the Admin Server. For more information, see the Physical Host Installation Guide or Virtual Host Installation Guide. If the service is not running, start the Endpoint Server.



The Hosts and Files views do not load in the Safari browser.


When you open the Ember pages in the Safari browser with a non-trusted SSL certificate, the Hosts and Files views do not load. To load the views.

1. Click the Show Certificate pop-up menu.

2. Enable the Always trust NetWitness when connecting to <IP Address> checkbox.

3. Click Continue.

4. Enter your username and password.

5. Click Update Settings.


MessageNo process information was found.
IssueWhen attempting to access the Process or Libraries tab in the Host Details view, the detailed host information is not available, and the view opens with the message.

Scan data is not available due to any of the following reasons:

  • First time scan is not complete

  • Data retention policy has deleted all scan snapshots

Files View Issues

BehaviorMeta values are taking time to load.
IssueMeta values are not set to index by values.

During investigation, while pivoting to the Navigate or Event Analysis view from the Files view, if the filename or hash (SHA256 and MD5) are not set to index by values, the matching results take time to load as the Concentrator must generate the index by accessing the meta database and retrieving value of the meta for each event. You have to manually index the values before pivoting.


IssueFiltering files takes a longer time to load results in the user interface.

In the Files view, while filtering files with the Contains operator, the results take a few seconds to load in the user interface. You must use at least one indexed field with the Equals operator while filtering the files.

You are here
Table of Contents > Troubleshooting Investigate