This website uses cookies. By clicking OK, you consent to the use of cookies. Click Here to learn more about how we use cookies.
OK
  • RSA.com
  • Products
    • Archer®
      • Archer®
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Archer® Exchange
      • Training
      • Upcoming Events
      • Videos
    • RSA® Fraud & Risk Intelligence Suite
      • RSA® Fraud & Risk Intelligence Suite
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Web Threat Detection
      • Upcoming Events
      • Videos
    • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Cloud
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Upcoming Patch Content
      • Videos
    • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication Mobile SDK
      • Advisories
      • Events
      • Ideas
      • Knowledge Base
      • Request Access
      • Training
    • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® Adaptive Authentication for eCommerce
      • RSA® Adaptive Authentication for eCommerce
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® FraudAction Services
      • RSA® FraudAction Services
      • Advisories
      • Discussions
      • Documentation
      • Ideas
      • Videos
    • RSA® Web Threat Detection
      • RSA® Web Threat Detection
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Videos
    • RSA NetWitness® Platform
      • RSA NetWitness® Platform
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Integrations
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • RSA NetWitness® Detect AI
      • RSA NetWitness® Detect AI
      • Documentation
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA NetWitness® Investigator
      • RSA NetWitness® Investigator
      • Documentation
      • Download the Client
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA NetWitness® Orchestrator
      • RSA NetWitness® Orchestrator
      • Overview
      • Documentation
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA SecurID® Suite
      • RSA SecurID® Suite
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Knowledge Base
      • Ideas
      • Integrations
      • Training
      • Videos
    • RSA® Identity Governance & Lifecycle
      • RSA® Identity Governance & Lifecycle
      • Advisories
      • Blog
      • Community Exchange
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • RSA SecurID® Access
      • RSA SecurID® Access
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Integrations
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • Other RSA® Products
      • Other RSA® Products
      • RSA® Access Manager
      • RSA® Data Loss Prevention
      • RSA® Digital Certificate Solutions
      • RSA enVision®
      • RSA® Federated Identity Manager
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
  • Resources
    • Advisories
      • Product Advisories on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Hosted
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Product Advisories
    • Blogs
      • Blogs on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Blogs on RSA Link
    • Discussion Forums
      • Discussion Forums
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Discussion Forums on RSA Link
    • Documentation
      • Product Documentation
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Documentation on RSA Link
    • Downloads
      • Product Downloads
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Downloads on RSA Link
    • Ideas
      • Idea Exchange
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Documentation on RSA Link
    • Knowledge Base
      • Knowledge Base
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Knowledge Base Pages on RSA Link
    • Upcoming Events on RSA Link
      • Upcoming Events
    • Videos
      • Videos on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Videos on RSA Link
  • Support
    • RSA Link Support
      • RSA Link Support
      • News & Announcements
      • Getting Started
      • Support Forum
      • Support Knowledge Base
      • Ideas & Suggestions
    • RSA Product Support
      • RSA Product Support
      • General Security Advisories and Statements
      • Product Life Cycle
      • Support Information
      •  
      •  
      •  
      •  
      •  
  • RSA Ready
  • RSA University
    • Certification Program
      • Certification Program
    • Course Catalogs
      • Course Catalogs
      • Archer®
      • RSA NetWitness® Platform
      • RSA SecurID® Suite
    • On-Demand Subscriptions
      • On-Demand Subscriptions
      • Archer®
      • RSA NetWitness® Platform
      • RSA SecurID® Suite
    • Product Training
      • Product Training
      • Archer®
      • RSA® Fraud & Risk Intelligence Suite
      • RSA® Identity Governance & Lifecycle
      • RSA NeWitness® Platform
      • RSA SecurID® Access
    • Student Resources
      • Student Resources
      • Access On-Demand Learning
      • Access Virtual Labs
      • Contact RSA University
      • Enrollments & Transcripts
      • Frequently Asked Questions
      • Getting Started
      • Learning Modalities
      • Payments & Cancellations
      • Private Training
      • Training Center Locations
      • Training Credits
      • YouTube Channel
    • Upcoming Events
      • Upcoming Events
      • Full Calendar
      • Conferences
      • Live Classroom Training
      • Live Virtual Classroom Training
      • Webinars
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

Visit the Known Issues dashboard if you are experiencing issues on RSA Link

View Dashboard

RSA enVision® Discussions

Browse the RSA enVision discussion board to get product help and collaborate with other users of RSA enVision.
  • RSA Link
  • :
  • Products
  • :
  • Other RSA Products
  • :
  • RSA enVision
  • :
  • Discussions
  • :
  • How to report from the enVision IPDB from RSA Secu...
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page
MatthewGardiner
MatthewGardiner Beginner
Beginner
‎2014-03-05 03:50 PM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

How to report from the enVision IPDB from RSA Security Analytics

With many customers in the midst of the transition from RSA envision to RSA Security Analytics we often get questions about whether and how the envision IPDB can be queried from the Security Analytics.  This write-up in the documentation give a good overview.  Enjoy!

 

 

https://sadocs.emc.com/0_en-us/095_10.3_User_Guide/13_Device_and_Service_Configuration/IPDB_Extracto...

 

 

And this link describes how to deploy the IPDB extractor service in a virtual deployment.

 

 

https://sadocs.emc.com/0_en-us/096_10.3_User_Guide_Supplement/90_Reporting_(SP1SP2)/Rule_Overview/02...

  • Tags:
  • analytics
  • Community Thread
  • Discussion
  • enVision
  • Forum Thread
  • IPDB
  • RSA enVision
  • Security
  • transition
0 Likes
Share
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
10 Replies
huanzhou1
huanzhou1 Beginner
Beginner
‎2014-03-08 08:55 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

the steps actually not really very clear, we spent lots of time troubleshooting.

0 Likes
Share
Reply
MatthewGardiner
MatthewGardiner Beginner
Beginner
In response to huanzhou1
‎2014-03-08 01:30 PM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

It would be great if you could provide here some of the steps you took to get the reporting working from the IPDB in Security Analytics.  That is a key value of this community.  I can then take your experiences and make sure they get to the RSA documentation team.

0 Likes
Share
Reply
huanzhou1
huanzhou1 Beginner
Beginner
In response to MatthewGardiner
‎2014-03-10 05:12 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Hi Matthew, the most headache part is the NAS sharing step, I tried whole afternoon and figured out need to share like below:

Share name: storage0 - Path: \vol0\nic\lsnode\data\LSIPDB-LC1

Share name: storage1 - Path: \vol1\nic\lsnode\data\LSIPDB-LC2

This step is missing from the dcoument, can we only share \vol0 or \vol1, please confirm.

 

After i configured the NAS, then i figured out why need put the storage mapping like below which specify in the sample:

\\1.1.1.1\vol1\nic\lsnode\LSIPDB-LC1~storage1,\\1.1.1.1\vol2\nic\lsnode\LSIPDB-LC1~storage2

 

Just additional, does IPDB extractor support to create report of multiple device types? As for now, i'm only able to create report of one device type only like rhlinux.

 

Thank you.

0 Likes
Share
Reply
huanzhou1
huanzhou1 Beginner
Beginner
In response to MatthewGardiner
‎2014-04-02 09:29 PM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Hi Matthew, can you help? I had an issue here, i was not able to finish the IPDB configuraiton using storage.mapping.

1. customer has 3 NAS vols used for envision: (vol0,vol1,vol2)

2. if I configured storage.mapping, i cannot get any event

3. if i directly map the vol0, i'm able to get the event

How should i specify the storage.mapping string? i have a case open but no reply yet.

 

And how to do debug? I used tcpdump but seems the ipdb extractor didn't access NAS.

 

Thank you.

0 Likes
Share
Reply
RSAAdmin
RSAAdmin Beginner
Beginner
In response to huanzhou1
‎2014-04-04 03:04 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Hi,

Looks like either the value of storage location is wrong or the mount points are wrong.

 

1) I suggest you to check this :

Mount IPDB in such a way that you have a path like this. If its not there, its for sure that you have wrong mounts and Storage locations configurations.

/var/netwitness/ipdbextractor/ipdb/<node name>/<storagelocation>/<device type>/<device>/<year>/<month> (in case you have multiple storage locations)

Or

/var/netwitness/ipdbextractor/ipdb/<node name>/<device type>/<device>/<year>/<month>   (single storage location)

 

2) I need the below info:

  • ‘Mapping of Storage Location’ config value
  • Mount points
  • Contents of /var/netwitness/ipdbextractor/ipdb ?
0 Likes
Share
Reply
huanzhou1
huanzhou1 Beginner
Beginner
In response to RSAAdmin
‎2014-04-04 09:43 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Hi Nehar,

1) I have below format, and i'm able to browser the event files.

/var/netwitness/ipdbextractor/ipdb/<node name>/<storagelocation>/<device type>/<device>/<year>/<month> (in case you have multiple storage locations)

//10.203.2.101/vol0 /var/netwitness/ipdbextractor/ipdb/ENT-ES/storage0 cifs auto,nouser,noexec,ro,prefixpath=/lsnode/data/ENT-ES,username=ipdbuser,password=password123 0 0

//10.203.2.101/vol1 /var/netwitness/ipdbextractor/ipdb/ENT-ES/storage1 cifs auto,nouser,noexec,ro,prefixpath=/lsnode/data/ENT-ES,username=ipdbuser,password=password123 0 0

//10.203.2.101/vol2 /var/netwitness/ipdbextractor/ipdb/ENT-ES/storage2 cifs auto,nouser,noexec,ro,prefixpath=/lsnode/data/ENT-ES,username=ipdbuser,password=password123 0 0

//%envision_ip%/csd /var/netwitness/ipdbextractor/devicelocation cifs auto,nouser,noexec,ro,username=ipdbuser,password=password123 0 0

2)  I tried below mapping

\\10.203.2.101\vol0\lsnode\data\ENT-ES~storage0,\\10.203.2.101\vol1\lsnode\data\ENT-ES~storage1,\\10.203.2.101\vol2\lsnode\data\ENT-ES~storage2

3)/var/netwitness/ipdbextractor/ipdb/ipdb/ENT-ES/storage0

/var/netwitness/ipdbextractor/ipdb/ipdb/ENT-ES/storage1

/var/netwitness/ipdbextractor/ipdb/ipdb/ENT-ES/storage2


Same configuration worked in another customer environment.

That's why strange enough, how to debug? I didn't see any network traffic to the NAS when doing rule testing.


If I mount only \\10.203.2.101\vol0\lsnode\data\ENT-ES to /var/netwitness/ipdbextractor/ipdb/ipdb/ENT-ES, then i tested the IPDB rule, it's working fine, i'm able to get events.




0 Likes
Share
Reply
RSAAdmin
RSAAdmin Beginner
Beginner
In response to huanzhou1
‎2014-04-07 02:18 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

I could see something is wrong here.

The path that gets created after you mount looks wrong. It should be some thing like this:


/var/netwitness/ipdbextractor/ipdb/<node name>/<storagelocation>/<device type>/<device>/<year>/<month>

i.e

/var/netwitness/ipdbextractor/ipdb/ENT-ES/storage0/<device type>/<device>/<year>/<month> (in your case)


But  I see that you have an extra "ipdb" directory:

/var/netwitness/ipdbextractor/ipdb/ipdb/ENT-ES/storage0

/var/netwitness/ipdbextractor/ipdb/ipdb/ENT-ES/storage1

/var/netwitness/ipdbextractor/ipdb/ipdb/ENT-ES/storage2


Your mount points look correct but since there is an extra "ipdb" directory getting created, I would suggest you to change the mounts in such a way that u have paths like this:

/var/netwitness/ipdbextractor/ipdb/ENT-ES/storage0

/var/netwitness/ipdbextractor/ipdb/ENT-ES/storage1

/var/netwitness/ipdbextractor/ipdb/ENT-ES/storage2


If you have manually created any extrac "ipdb" directly, please delete the same.


After resolving this, try running a report. I think it should work.

Do let me know the result.


0 Likes
Share
Reply
huanzhou1
huanzhou1 Beginner
Beginner
In response to RSAAdmin
‎2014-04-07 04:10 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Sorry, typo. The actual one is below, i have the screenshot, if you ok,i can send to you for renew.

 

/var/netwitness/ipdbextractor/ipdb/ENT-ES/storage0

/var/netwitness/ipdbextractor/ipdb/ENT-ES/storage1

/var/netwitness/ipdbextractor/ipdb/ENT-ES/storage2

I opened a support case but no reply so far.  So no choice, i only configured one storage only.

0 Likes
Share
Reply
RSAAdmin
RSAAdmin Beginner
Beginner
In response to huanzhou1
‎2014-04-07 04:16 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Ok. Then the mounting is correct. I assume that after storage0/storage1/storage2 u have a path like <device type>/<device>/<year>/<month>and have ipdb .dat files there.


You should also check if the storage mappings are correct. For that do the following:

Login to your envision UI and go to :

System Configurations->Directories->Manage Storage Locations


This will give the directory paths to which you should map storage0, storage1 and storage2.

Check if the mapping you configured are correct.

If not, correct them and restart ipdb extractor service.

Execute a report and check.

0 Likes
Share
Reply
  • « Previous
    • 1
    • 2
  • Next »
  • « Previous
    • 1
    • 2
  • Next »
Powered by Khoros
  • Products
  • Resources
  • Solutions
  • RSA University
  • Support
  • RSA Labs
  • RSA Ready
  • About RSA Link
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
© 2020 RSA Security LLC or its affiliates.
All rights reserved.