I want to send meta data from NetWitness to splunk. I have contacted RSA to obtain documentation that can guide me through, but I was told that they have solution for SA not for the version of NW that I am currently runing.(NextGen 9.8.5.19)
Does anybody have integrated NW to Spluk? Can you share how its done easily? I need your assistance to accomplish this task.
Thank you all.
There are 3 apps that all work both with SA and NW as the REST API hasn't changed since 9.8.5.9 when it was released.
You can find them here http://apps.splunk.com/apps/#/search/netwitness
Hope that helps!
Regards,
Rui