When managing the web interface, users with the Senior security officer role can download raw network traffic dumps in PCAP format from servers with the Sensor component and conduct investigations to detect suspicious activity.
If you are using the distributed solution and multitenancy mode, follow the steps on the PCN or SCN server to which the server with the Sensor component is connected.
To download raw network traffic captured from network interfaces:
The Server list table will be displayed.
This opens the Sensor component settings page.
By default, all network interfaces are selected.
If in the SPAN traffic scanning column, the toggle switch to the right of the network interface name is set to Disabled, you cannot download raw network traffic dumps from that network interface.
This opens the raw network traffic download settings settings window.
In this window, the First saved dump field displays the date and time of the first saved raw network traffic dump, and the Last saved dump field displays the date and time of the last raw network traffic dump. In the Available dump storage space field, the first number indicates the free space in dump storage, and the second number indicates the total size of the dump storage.
If recorded traffic does not exist for your selected period, when you click Download, Kaspersky Anti Targeted Attack Platform suggests selecting the period from the first recorded network traffic dump to the last. If no recorded dumps of raw network traffic exist at all, a warning is displayed indicating the lack of data for the specified period.
The default value is 100 MB. The minimum value is 1 MB, and the maximum value is 1,000,000 TB. The downloaded raw network traffic dump of the specified size contain data starting with the last record of the selected period.
By default, the toggle switch is in the Disabled position.
Example of a filtering expression:
tcp port 102 or tcp port 502
By default, the toggle switch is in the Disabled position.
Example of a filtering expression:
^test.+xABxCD
Raw network traffic dumps are downloaded in PCAP format.
Page top