Skip to content
  • There are no suggestions because the search field is empty.

QuickStart

What is NetWitness UEBA?

NetWitness UEBA (User and Entity Behavior Analytics) is an advanced analytics solution for discovering, investigating, and monitoring risky behaviors across all users and entities in your network environment. NetWitness UEBA is used for following reasons:

  • Detecting malicious and rogue users
  • Pinpointing high-risk behaviors
  • Discovering attacks
  • Investigating emerging security threats
  • Identify potential attacker activity

About this Guide

This guide provides end-to-end instructions to configure NetWitness UEBA and to use UEBA features.

Getting Started

The following tasks can be performed in any sequence.

  • Description:

    netwitness_analyst_50x55.png


  • Description:

    View information about product updates, improvements, and known issues.

  • References:

    Release Notes



Setup and Installation

You can setup and install NetWitness UEBA by performing Standalone Installation and Fresh Installation.

Standalone Installation

The following tasks must be performed in the following sequence.

  • Description:

    netwitness_analyst_50x55.png









Fresh Installation

The following tasks needs to be performed in the following sequence.

  • Description:

    netwitness_analyst_50x55.png



  • Description:

    Review the UEBA architecture.

  • References:

    "NetWitness Platform Network Architecture Diagram" topic in the Deployment Guide


  • Description:

    Configure the ports on your firewall.

  • References:

    "Network Architecture and Ports" topic in the Deployment Guide


  • Description:

    Install NetWitness Server host and other components.

  • References:

    "Task 1 - Install 12.5 on the NetWitness Server (NW Server) Host" and "Task 2 - Install 12.5 on Other Component Hosts" in Physical Host Installation Guide

    "Install NetWitness Platform Virtual Host in Virtual Environment" in the Virtual Host Installation Guide




Update

The following tasks must be performed in the following sequence.

  • Description:

    netwitness_analyst_50x55.png


  • Description:

    Deploy the Endpoint Pack from Live, which contains

    File Category Lua Parser for the UEBA integration with Endpoint.

  • References:

    During deployment, you must specify Endpoint Log Hybrid Log Decoder service. In case of multiple Endpoint servers, select all the Endpoint Log Hybrid Log Decoder services


  • Description:

    Enable Endpoint data sources such as Process and Registry to generate alerts in UEBA.

  • References: "ueba-server-config script" in the UEBA Configuration Guide

  • Description: Enable UEBA indicator forwarder to transfer the UEBA indicators to the NetWitness Respond server and to the correlation server to create an incidents.
  • References:

    "ueba-server-config script" in the UEBA Configuration Guide


  • Description:

    After you update to NetWitness Platform 12.4 the Broker or Concentrator UUID changes. You must update the NetWitness Platform core services, and update the Broker or Concentrator UUID.

  • References:

    "ueba-server-config script" in the UEBA Configuration Guide



  • Description:

    Restart the Airflow scheduler service after the presidio_upgrade DAG is successful.

  • References:

    "reset-presidio script" in the UEBA Configuration Guide


Investigation

The following tasks can be performed in any sequence.

  • Description:

    netwitness_analyst_50x55.png




Monitoring

The following tasks can be performed in any sequence.

  • Description:

    netwitness_analyst_50x55.png


  • Description: Review NetWitness UEBA metrics in Health and Wellness.
  • References: "View NetWitness UEBA Metrics in Health and Wellness" topic in the NetWitness UEBA User Guide

  • Description: Monitor Health and Wellness of UEBA.
  • References: "Monitor Health and Wellness of UEBA" topic in the NetWitness UEBA User Guide

Getting Help with NetWitness Platform

There are several options that provide you with help as you need it for installing and using NetWitness:

Use these links to access documentation that is not related to a particular version of the software: