The NetWitness Query App for Splunk connects to a NetWitness Concentrator, facilitating regular polling of the NetWitness API to gather new session meta data. The collected meta data can be subsequently indexed by Splunk, ensuring timely analysis and processing. The application offers two distinct polling options to cater to diverse requirements. Users can opt to collect either all the recently available session meta data or selectively retrieve specific meta data from NetWitness.
(0)
Categories
Created By
Type
Downloads
Licensing
Splunk Answers
Resources