2014-06-25
11:56 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
payload of the packet with ESA rules?
Does anybody know how to look in the payload of the packet with ESA rules?
I have looked at rules and they rule D.payload but they just use common metakeys, I want to look in the content of the packet.
- Tags:
- anaytics
- Community Thread
- Discussion
- ESA
- Forum Thread
- NetWitness
- NW
- NWP
- RSA NetWitness
- RSA NetWitness Platform
- Security
1 Reply
2014-06-30
11:39 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
ESA only works with meta.
To look for something in the packet payload, you should use a parser / app rule on the decoder to generate meta, and then use an ESA rule on meta you generate.
