I have a customer running NW for Log and he needs to know the date and time of the first event saw in the platform for each event source... How can I achieve that?
Thanks in advance
you should use a report with:
Rule Type: NetWitness DB
Name: First event of each event source
Select: event.source, first(time)
Where: event.source exists
Group by: event.source
not all events have event.source metadata, If you are interested in all the events saw in the platform, you should use device.ip or device.host instead of event.source
Ciao Roberto, thank you so much for your response. I going to try it and I will let you know the results.
Retrieving data ...