Hi ,
Please let me know how parser works in netwitness, means when a log file comes what is the process it goes through to go to the actual parser.. Means there are n number of parsers so how a log file travels to parser , how parser parses the file, it matches headers first or headers and payload both, means how exactly it matches the events to the definitions.
Hi Sonam,
Parsers are matched to devices based on internal scoring from header matches.
The log gets matched to a header first.
You can force match a device with parser using device mapping.
For more details, refer:https://community.rsa.com/docs/DOC-83456
Regards,
Twinkle