- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
is there any issue in SA 10.3?
i just integrated two HPUnix in my SA server then i got, logs are coming as two different device type,refer attached screen shot
is this issue of SA or event source?
- Tags:
- analytics
- Community Thread
- Discussion
- Forum Thread
- NetWitness
- NW
- NWP
- rsa
- RSA NetWitness
- RSA NetWitness Platform
- Security
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi there.
So, we had an issue with a load balancer showing up as a Junos Router because it was running Junos OS. If your device is running a Junos/Juniper OS, it's being parsed as a Junos device. It's a parsing issue, and you need to tweak your parser to acknowledge the issue, or escalate to RSA's dev team. Hope this helps
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
i think its source, check the session details
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
authentication success log come under HPUnx or authentication failure log coming under junosrouter from same device ip
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
can you post the sample event? looks like both parser hpux and junosrouter enabled.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Just wondering whether your network has junosrouter or not, which sent the events to SA?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
no junos router, just check devcie ip, hp unix and junosrouter is same
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
can you export all the logs?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi there.
So, we had an issue with a load balancer showing up as a Junos Router because it was running Junos OS. If your device is running a Junos/Juniper OS, it's being parsed as a Junos device. It's a parsing issue, and you need to tweak your parser to acknowledge the issue, or escalate to RSA's dev team. Hope this helps
