The application saves traffic received through monitoring points as traffic dump files. The application uses these files for analysis of incoming traffic. You can also use these files to perform the following actions in the application:
Traffic dump files are saved in internal storage on servers with the Sensor component. If you use the Central Node component with built-in Sensor, traffic dump files are saved in the internal storage of the Central Node server.
The application stores traffic dump files on a temporary basis. As traffic arrives, the application automatically deletes the oldest traffic dump files from storages if the total size of files approaches the limit set for the storage. You can configure the settings for storing traffic in the internal storage.
To configure the saving of traffic dump files to the internal storage:
This opens a window with information about the component.
Filtering can reduce the size of stored traffic by discarding network packets that do not match the filter. However, if you rely on filtering, consider that filtered traffic may not provide all data that the application needs for high-quality traffic analysis. You need to configure filtering in such a way that all network packets that the application needs to analyze traffic are saved in the traffic dump files.
You can select the unit of measure for the space limit: MB or GB.
When editing the value, you also need to take into account the amount of received traffic, the rate at which it is received, and the fact that the sum total of all size limits may not exceed the specified maximum storage capacity for the node.
Traffic dump saving in internal storage is configured.
Page top