The General settings let you set up and configure the general capture options.
- Capture to disk: This option is selected by default and saves
packet files on your disk. The packet files saved to your hard disk can be opened
and analyzed at a later time.
- Intelligent CTD: Select this option to reduce the
amount of data stored to disk and increase your retention time by
intelligently slicing off encrypted payloads. It does this by tracking
flows—if a flow is encrypted, the full data for the first 20 packets is kept
and the payload from the rest of the packets is sliced. It keeps the first
20 without slicing so the certificate exchange is always
included.
Intelligent CTD is an advanced feature that provides significant benefits to network security and data retention. It reduces the amount of data stored on disk and increases retention time by intelligently slicing off encrypted payloads, which helps to conserve storage space and improve system performance.
The way Intelligent CTD works is by tracking flows on the network. When a flow is detected as encrypted, Intelligent CTD keeps the full data for the first 20 packets and slices the payload from the rest of the packets. This ensures that the certificate exchange is always included in the data, which is critical for identifying encrypted traffic and providing context for analysis. The benefits of Intelligent CTD are numerous. Firstly, it helps to optimize storage usage, as the system doesn't store unnecessary data. This helps to reduce the cost of storage and improve system performance by reducing the amount of data that needs to be processed. Secondly, Intelligent CTD helps to improve retention time.
By conserving storage space, it enables organizations to retain data for longer periods, which can be critical for compliance and regulatory requirements. This also enables organizations to perform more in-depth analysis of data, which can provide valuable insights into network activity and help to identify potential threats. Thirdly, Intelligent CTD helps to maintain privacy and compliance. By keeping the certificate exchange in the data, it ensures that the system can identify encrypted traffic and provide context for analysis, without compromising the privacy of users. This helps organizations to comply with privacy regulations and maintain the trust of their users.
Overall, Intelligent CTD is a powerful feature that provides numerous benefits to network security and data retention. By intelligently slicing off encrypted payloads, it helps to optimize storage usage, improve retention time, and maintain privacy and compliance.
- Compression: Select this option to compress blocks of packets before writing them to the file. This setting is only available when you are capturing from a capture card that supports this feature, and only when you are saving files to the .npkt file format.
- Intelligent CTD: Select this option to reduce the
amount of data stored to disk and increase your retention time by
intelligently slicing off encrypted payloads. It does this by tracking
flows—if a flow is encrypted, the full data for the first 20 packets is kept
and the payload from the rest of the packets is sliced. It keeps the first
20 without slicing so the certificate exchange is always
included.
- File name: Type the name used as a base file name prefix for each capture file that is created using the Capture to disk option. Additionally, each capture file is appended with a timestamp indicating the date and time the file was saved. The format of the timestamp is YYYY-MM-DD-HH.MM.SS.mmm.
- File size (MB): Enter or select the maximum file size before a new file is created.
- Disk space for this capture: Move the slider control to set the amount of hard disk space allocated for the capture. The minimum value of the slider is the minimum size of disk space a capture can occupy.