Skip navigation
Log in to create and rate content, and to follow, bookmark, and share content with other members.

Investigate: Troubleshooting Investigate

Document created by RSA Information Design and Development Employee on Mar 27, 2018Last modified by RSA Information Design and Development Employee on Apr 23, 2020
Version 13Show Document
  • View in full screen mode
 

This section provides information about possible issues when using NetWitness Investigate.

Navigate View and Legacy Events View Issues

 

                   
Behavior

A meta key that normally returns values in the Navigate view returns values, but has a Not Indexed message following the meta key name. For example, the in this figure the Service Type meta key is followed by the message: Service Type[service] Not Indexed.

Not Indexed message 

Issue

When you first set up the environment or very rarely after performing a data reset on the broker due to other issues, you see meta keys as Not Indexed when they are indexed at meta key or meta values level.

Explanation

To fix the issue on a Broker, log out of NetWitness Platform and then log in again. Valid sessions will be displayed.

 

                 
MessageNot indexed; will experience longer than usual load times. in the Manage Meta Groups dialog.
Issue

Meta keys in the Manage Meta Groups dialog are marked by a red exclamation point, and the error message is displayed. This can occur when investigating a Broker or Decoder while adding a meta group with meta keys that are not indexed in the index file or the custom index file for the service.

For a Broker, it could mean that the Broker has not begun aggregating data from a Concentrator. In this case the Broker will not have the contents of the custom index file from the aggregate services and the keys will not be indexed.

For a Decoder, it means that the meta keys are not indexed in the Decoder index or custom index file.

Explanation

To fix the issue on a Broker, log out, log in, and restart the Broker service so that it can aggregate the meta key information from connected Concentrators. To fix the issue on a Decoder, edit the custom index file to index the meta keys, log out, log in, and restart the Decoder service.

 

                 
Behavior

When downloaded from the Event Reconstruction view, logs and metadata are always in text format irrespective of the format selected in the Legacy Events view.

Issue

When you download metadata or a log in the Event Reconstruction view, the format that you selected in the Legacy Events view is not used. The exported data is always in text format.

Explanation

Download metadata and logs from the Legacy Events view if you want to use a format other than text format.

 

Events View Issues

 

                 
MessageApplicable for hosts with 4.x Endpoint agents installed, please install the NetWitness Endpoint Thick Client.
IssueWhen you click Pivot to Endpoint in the Events view, no data is displayed and the message is displayed.
ExplanationVersion 4.4 of the NetWitness Endpoint Thick Client must be installed on the same server, the NWE meta keys must exist in the table-map.xml file on the Log Decoder, and the index-concentrator-custom.xml file on the Concentrator. The NWE Thick Client is a Windows only application. Complete setup instructions are provided in the NetWitness Endpoint User Guide for Version 4.4.

 

                 
BehaviorDownload jobs are in a Waiting state or Failed state in the Jobs tray during and after upgrading the software to Version 11.4.
IssueIf you had download jobs running while your administrator was upgrading the software, you may see a job in a Waiting state while the upgrade is in progress and then in a Failed state after the upgrade is complete. You cannot resume or cancel the failed job.
ExplanationTo delete the failed jobs, select the failed jobs in the Jobs tray and clickDelete button.

 

                 
MessageEvent Analysis requires all core services to be NetWitness 11.1. Connecting prior versions of services to the 11.1 NetWitness Server results in limited functionality (see "Investigate in Mixed Mode" in the Physical Host Upgrade Guide).
IssueWhen attempting to investigate a service that has not been updated to Version 11.1 in the Event Analysis view, the informational message is displayed.
ExplanationWhen an analyst opens the Event Analysis view in mixed mode (that is, some services are upgraded to 11.1 and later, and some are still on 11.0.0.x or 10.6.x), Role-Based Access (RBAC) is not applied uniformly. This affects viewing and downloading content, and validation of filters in the interactive breadcrumb. You will see this informational message when you open Events. As you select a service, services that are not up to date are displayed in a red box, with the message that the service is not up to date. When your administrator has upgraded all connected services to 11.1 and later, these features work as expected.

 

                 
MessageForbidden. You cannot access the requested page.
IssueWhen attempting to access the Events view, the view opens with the message.
ExplanationYour administrator has prevented access to the Events view using role and permissions.

 

                 
BehaviorIf you can download an event in the Events view, but get a 0-byte file, the administrator may have restricted access to the content.
IssueRole-Based Access Controls applied by your administrator allowed you to download an event for which you did not have permission; therefore, the file download was empty.
ExplanationIf you believe you should have access to the event, contact your administrator.

 

                 
Message

Insufficient permissions for the requested data.

IssueWhile attempting to access an event in the Events view, the message is displayed.
ExplanationYou have entered an event ID for an event that you do not have permission to view. The administrator may have placed some restrictions to limit access by role and permissions.

 

                 
MessageInvalid session ID: <<eventId>>
IssueNo sessionId matches the sessionId that you queried.
ExplanationThe reason for an invalid session ID can vary. Perhaps you edited the session ID manually, and no such session exists. Another case may be when you query a Broker, and the aggregated data has not been refreshed, you may see this error for a session that no longer exists.

 

                 
BehaviorInvestigation Profiles and built-in column groups are not present in 11.1 Event Analysis.
IssuePost upgrade to RSA NetWitness v11.1, the default column groups - Endpoint Analysis, Outbound SSL and Outbound HTTP are not added under column groups. Also, a few of the Investigation Profiles are missing post upgrade.
Explanation

It is observed that this issue occurs only when you have created a custom column group with the name which is same as one of the new 11.1 OOTB custom column group name. For example, if you create a custom column group in 11.0 with name RSA Endpoint Analysis then after upgrade to 11.1. Due to the same name already existing in 11.1, OOTB column groups and built-in profiles will not be available in the UI.

To fix this, change the name of custom column group to something other than one of the OOTB column groups and restart the jetty server by using the following command on the NetWitness server:

systemctl restart jetty

 

                 
MessageMemory limit of <XXXXXX> GB reached, controlled by setting max.query.memory
IssueThe query that you submitted failed because the result set was too large, and the memory limit set by max.query.memory was reached.
ExplanationTo avoid this error, try to further limit results by narrowing the time range, adding filters, and decreasing the number of columns in the column group. You can also ask an administrator to limit the number of events returned.

 

                 
BehaviorNo text data was generated during content reconstruction. This could mean that the event data was corrupt or invalid, or that an administrator has disabled the transmission of raw endpoint events in the Endpoint server configuration. Check the other reconstruction views.
IssueWhen you reconstruct an event as text in the Events view, no data is displayed and the message is displayed.
ExplanationIf you do not see the raw text in other Events views or Legacy Events view reconstructions, and you believe the data is not corrupted or invalid, your administrator has likely disabled transmission of raw endpoint events on the NetWitness Endpoint server. Contact your administrator for additional information.

 

                   
Message

Rule Syntax error: Unrecognized key "<meta key or meta entity name>"

Syntax error: Unrecognized key "<meta key or meta entity name>"

Issue

While querying a service, the matching events are not listed and the message is displayed in the query console and the Events view.

error message due to a misconfigured entity 

ExplanationThe query you entered is querying a meta entity that is not configured properly. All upstream devices connected to the Broker being queries should have the same entity configuration. This error indicates that the Broker is operating with mismatched entity definitions. Ask your administrator to review the configuration described in "Index Customization" in the Core Database Tuning Guide.

 

                 
Message

Selected Column Group is no longer available. The default summary column group has been selected instead.

IssueIf you had set a preferred column group before the 11.4 upgrade, on your first visit to the Events view, the flash message is displayed even when the column group is available or is the default group (summary). This issue was resolved in Version 11.4.1.
ExplanationThis is a one-time occurrence. If you reload the Events view, the message is not displayed.

 

                 
Message

Session is unavailable for viewing.

IssueWhile querying an event ID, the reconstruction is not displayed and the message is displayed.
ExplanationThe query you entered is trying to look at restricted data, for example, if you are allowed to see only log data and you are using a link to network data .

 

                 
MessageThe query on channel <channel-number> was auto-canceled by the system for exceeding time usage limits. Check timeout values. Query running time was 00:05:00 (HH:MM:SS)
IssueIf you continually get this timeout message, first check the query console to determine if there are issues around time it takes for a service to respond, index error messages, or other warnings that may need to be addressed to increase query response time.
ExplanationIf there are no messages indicating any specific warnings, ask your administrator to increase the Core Query Timeout from 5 minutes to 10 minutes as described in the System Security and User Management Guide.

 

                 
MessageThe session id is too large to be handled:<<eventId>
IssueThe session id that you typed in, or got from the Legacy Events view or Navigate view is too large.
ExplanationIf you manually typed the sessionId or edited a sessionId in the Events view, you may have created an integer that is too large for Events to process.

 

                 
Behavior

When reconstructing network events with a large number of packets (>250) in the Events view > Packets panel, with the option to display only payloads enabled and the packets per page setting higher than the default (100), the current browser tab may become unresponsive for up to 45 seconds as it is working to render the payloads.

Issue

Depending on the amount of resources (memory and CPU) on the client machine and the number of packets in the event there may be a performance lag when displaying only payloads in packet reconstruction.

Explanation

To limit the amount of data processed in a reconstruction of a single event, change the Packets per Page setting in the footer to a lower value.

the Packets per Page setting

 

                 
BehaviorWhen working in the Version 11.4 Events view, the Query Profile drop-down menu and Column Group drop-down menu do not function.
IssueYou do not have permission to read columns groups and profiles. The default column group , Summary List, is applied to the Events list, and you cannot change the column group, create a column group, or delete a column group.
ExplanationThis occurs only when the administrator has created a custom role for you instead of assigning the default Analyst role. Ask your administrator to enable column group read and profile read permission for your role.

 

You are here
Table of Contents > Troubleshooting Investigate

Attachments

    Outcomes