This document applies to Classic/Legacy Integrations. You may continue to use these integration configurations. While no active development is happening for these integrations, we continue to provide Classic/Legacy Integrations in the product. You do not have to move to MSI Integrations. If your support engineer or TSC recommends or you choose to move to MSI Integrations, you can take advantage of the latest features and functionality. For more information, see the MSI Integration documentation in the Integrations Overview.
Update the Validation Platform
Prerequisites
Information to gather before you start:
- IP address used to access the RSA NetWitness concentrator.
- Port for the concentrator communication (default is 50105).
- Identify whether the protocol is HTTP or HTTPS for connections to the RSA NetWitness concentrator port.
- Identify or create the credentials to access RSA NetWitness's concentrator.
Identify the field name mappings for the following:
There could be multiple of each, depending on log sources and configuration.- Source IP
- Destination IP
- Source Port
- Destination Port
- Event Start Time (timestamp)
- Event Unique ID
- Event Signature ID
- Event Description
- Event Source Host
Configuration
To add the RSA NetWitness integration
Go to Settings > Integrations.
Click Add Integration > RSA NetWitness.
Enter information for the Host, Port, Protocol, Username and Password or API Token.
- (Optional) Enter information in the Query dialog box to query for base events. Click Show default query to see the default query information.
Expand Advanced options.
- (Optional) Update the User Agent.
To enable a query for ESA alerts, check the Enable query for Alerts check box.
(Optional) Enter information in the Alert Query dialog box to query for ESA alerts.
The default time for an alert can be up to 30 minutes off from when the event fired. If this is the case you must add another field to your alerts with the proper time and add that time to the start_time field map for correlations to work properly.Review the field name mappings; update as necessary.
- Inputs are enclosed by square brackets
[]. - Inputs are columns that could contain the info (
["time"]). - If there could be multiple commas, enclosed in one set of brackets, encompassed in quotes, and separated by commas (
["msg.id","reference.id", "rid"]).
- Inputs are enclosed by square brackets
(Optional) Assign a Name.
(Optional) Choose Yes to save suspicious events.
Click Submit.
Verify Connectivity
To verify connectivity to RSA NetWitness
Click Test to verify that:
- The Director can communicate with NetWitness on the port and protocol specified.
- Credentials are valid and working.

