Skip to content
  • There are no suggestions because the search field is empty.

NetWitness Malware Analysis does not scan any files

Issue

The NetWitness Malware Analysis is not processing any events on continuous scan mode.

Looking at the /var/lib/netwitness/malware-analytics-server/spectrum/logs/spectrum.log, it is showing that no events are being submitted to be processed.




Cause

Issue is caused by the two required App Rules  spectrum.consume and  spectrum.consume1.1 are not deployed on the Packet Decoders. These App Rules determine which sessions/events are to be submitted to the Malware Analysis for processing.

Resolution

1. In NetWitness UI, go to Configure > Live Content > Click on MALWARE ANALYSIS > Click Search

2. Then subscribe and deploy all resources found to the packet decoders.  

Below is a screenshot of Live search with Malware Analysis selected:
image.png

Product Details

NetWitness Product Set: NetWitness Platform
NetWitness Product/Service Type: Malware Analysis
NetWitness Version/Condition: 11.x, 12.x
Platform: CentOS
O/S Version: 7

Approval Reviewer Queue

Technical approval queue