Hello,
I am relying heavily on geographic information presented within Investigator, mainly source and dest city, organization and such.
Is the DB used by Investigator updated on a regular basis, and can I download the updates into my network?
I am using Investigator on a computer not connected to the internet.
Thank you,
John.
Hi John,
They are actually named "GeoCity.dat", "GeoCountry.dat", "GeoDomain.dat" and "GeoOrg.dat" and they normally reside on:
Win7 : \ProgramData\NetWitness\
Win7 : \Users\All Users\NetWitness\ (additional copy)
Win2K3 : \Documents and Settings\All Users\Application Data\NetWitness\
Those are the two OSes that I have immediate access to check but should give you a fairly good idea of where they live for most Windows based systems.
Only City and Country have Lite (i.e. free versions from MaxMind), Domain and Org are subscription only.
Hope that helps!
Regards,
Rui