Skip to content
  • There are no suggestions because the search field is empty.

How to view Incident name with ESA alert name

Issue

All incidents name appears with for details by default. (shown below)

Name

This is due to Group by value set "Source IP Address" as default parameter in Incident Rules.

Resolution

Please follow below steps to get Incident Name with ESA alert title.
  1. 1. Login to Netwitness GUI.
  2. 2. Navigate to CONFIGURE->Incident Rules to view list of rules.
  3. 3. Edit the rule wish to change the Name.
  4. 4. Locate GROUPING OPTIONS-> GROUP BY and Select "Alert Name" from drop down as below and Save rule.
    Grouping
     
  5. 5. Verify new incidents comes with ESA alert title in Incident name as below by Navigating to RESPOND->Incidents page.
    ESA



     

Product Details

RSA Product Set: NetWitness Logs & Network
RSA Version/Condition: 11.x
Platform: CentOS
O/S Version: 7

Summary

This article outlines the procedure to show ESA alert title in Incident name.


Approval Reviewer Queue

RSA NetWitness Suite Approval Queue