custom inject log report
I have injected custom logs under RSA SA for some old dates and trying to run report on the same using "event_time" meta.
Once logs uploaded, i can view current time in "time" meta and old time in "event_time" meta.
Copied the avro to the date folder i want report for but report appears blank.
On 5 Mar, i have inject logs of 05 Jan using nwlogplayer under Decoder. Logs populated under Conc properly like "time" meta reflecting 5 Mar and "event_time" meta reflecting 05 Jan. Now copied avro of 05 Mar and paste to 05 Jan and trying to run the report using "event_time" meta on 05 Jan time period.
Report appearing blank.
Need support on the same on how i can able to view logs or any suggestion which can help me to achieve it.
- Community Thread
- Forum Thread
- RSA NetWitness
- RSA NetWitness Platform
- sa report
The issue is when you inject the data into the system you loose the original collected date time
There are steps that I outlined in a diff post on how to do this.
I can get you the link shortly if you can’t find it