Skip to content
  • There are no suggestions because the search field is empty.

How to download raw logs from the Archiver in RSA Security Analytics/NetWitness Platform

Issue

This article describes how to download raw logs from an RSA Security Analytics/NetWitness Platform Archiver appliance, and provides a sample for doing so against a specific time range.


Resolution

  1. Connect to the Archiver REST API using the following address:
http://{archiver hostname or ip}:50108/sdk/packets
  1. Enter an administrator's username and password when prompted.
  2. A screen similar to the one shown below will be seen.  You can enter selection criteria, such as a time range and device type:
User-added
  1. To download raw logs for a specific device, insert device.type= as in the example above.
  2. Optionally, you can specify a time range where the time format is YYYY-MMM-DD HH:MM:SS in UTC.  For example, "2019-Sep-20 11:19:00" in UTC.
  3. Select the extract format type.
  4. Click Submit when done.

Product Details

RSA Product Set: Security Analytics / NetWitness Platform
RSA Product/Service Type: Archiver, REST API
RSA Version/Condition: 10.6.X, 11.X
Platform: CentOS
O/S Version: 6, 7

Summary

This article describes how to download raw logs from an RSA Security Analytics/NetWitness Platform Archiver.


Approval Reviewer Queue

RSA NetWitness Suite Approval Queue