Skip to content
  • There are no suggestions because the search field is empty.

Build Your Own Integration

This document will serve to aggregate useful how-to information for "Do-It-Yourself" creation of parsers and integrations for RSA NetWitness Platform.  Please follow the page for updates using the Actions menu above as we will be adding more content frequently.  Also, please feel free to add comments below or click the Send Feedback button to provide feedback, request new content or to let us know about any new posts which would be useful to reference here.





  • Resource: JSON Development Guide 
  • Description: Collecting JSON logs via file collection method (available as of 11.3)

  • Resource: Custom (File Collection) Typespec
  • Description: Detailed instructions and specifications for creating a typespec to transform file-based log sources for proper parsing.

  • Resource: Custom File and ODBC Typespec Demo Video
  • Description: Walkthrough video on creating your own typespec for collecting file and ODBC log sources.  NOTE: This video is a bit old, but still gives a good demonstration of how the process works.

  • Resource: Log Parser Tool Downloads
  • Description: Download the free tool for creating full XML parsers for your custom event sources


  • Resource: Event Time Function Usage
  • Description: Using the Event Time function within an XML parser to parse different date formats into TimeT type.


  • Resource: RSA Training: Lua Parsers for Logs
  • Description: Lua parsers aren't just for packets.  Take in-depth training from RSA on how to leverage Lua to solve challenging log parsing problems.

  • Resource: Plugins Development Guide
  • Description: Detailed instructions and specifications for creating a Plugin to collect and transform cloud-based, API-accessible log sources for proper parsing.

Managing Meta

  • Resource: Custom Table-Map Maintenance
  • Description: Instructions on properly configuring the custom table map to manage keys populated by log parsers.  NOTE: The index-concentrator-custom.xml files will sometimes also need to be modified to achieve indexing and full searchability of meta keys.




RSA NetWitness Platform Open API






 

docFeedback.png

You can also leave feedback in the comments below.  Help us enable you to find creative solutions to your integration goals!