Welcome to the new Splunkbase! To return to the old Splunkbase, click here.
NetWitness Query App for Splunk app icon

NetWitness Query App for Splunk

The NetWitness Query App for Splunk connects to a NetWitness Concentrator, facilitating regular polling of the NetWitness API to gather new session meta data. The collected meta data can be subsequently indexed by Splunk, ensuring timely analysis and processing. The application offers two distinct polling options to cater to diverse requirements. Users can opt to collect either all the recently available session meta data or selectively retrieve specific meta data from NetWitness.

splunk product badge

Compatibility
Not Available
Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 3.x
Rating

0

(0)

Log in to rate this app
The NetWitness Query App for Splunk connects to a NetWitness Concentrator, facilitating regular polling of the NetWitness API to gather new session meta data. The collected meta data can be subsequently indexed by Splunk, ensuring timely analysis and processing. The application offers two distinct polling options to cater to diverse requirements. Users can opt to collect either all the recently available session meta data or selectively retrieve specific meta data from NetWitness.

Categories

Created By

NetWitness Platform

Type

app

Downloads

266

Resources

Login to report this app listing