This section describes how to finish the integration of Kaspersky CyberTrace with RSA NetWitness after the files of Kaspersky Threat Feed Service for RSA NetWitness are upgraded to the files of Kaspersky CyberTrace.
To integrate Kaspersky CyberTrace with RSA NetWitness after Kaspersky Threat Feed Service for NetWitness'files are upgraded to Kaspersky CyberTrace files:
/etc/netwitness/ng/envision/etc/devices/ktfs
directory from the computer on which Log Decoder runs.integraton/cybertrace
directory of the Kaspersky CyberTrace distribution kit to the /etc/netwitness/ng/envision/etc/devices
directory.context
) are present in the following files:If any fields are absent, refer to section "Troubleshooting".
KTFS
" in the following order:Importing rules
In the Import Rule window, select Rule and List to overwrite the existing data and then click the Import button.
KTFS_META_GROUP
meta group, as follows:The Manage Meta Groups window opens.
KTFS_META_GROUP
meta group and click the Delete button ().
Removing a meta group
CyberTrace_META_GROUP
meta group.