Limitations with RCE configurations - User Guide - LiveWire - 26.2.0

LiveWire User Guide

ft:locale
en-US
Product name
LiveWire
Version
26.2.0

The following limitations exist with the Remote Capture Engine configuration:

LiveWire control point

  • The LiveWire control point can support up to 150,000 LiveWire RCEs in its Engine View.
    Attention: The LiveWire control point requires at least 6 CPUs and 20 GB of memory to support up to 150,000 LiveWire RCEs.
  • When a LiveWire RCE has been added to a LiveWire control point, LiveWire RCEs are not included in the following locations on the LiveWire control point UI:
    • The Engines List view in the sidebar
    • The Distributed forensic search page.
    • The Multi-segment analysis page.
    • The Engine configuration sync page.
    • The Copy Files or Move Files dialog from the Captures or Files view.
  • LiveWire control points will not be able to capture packets.

LiveWire RCE

  • The LiveWire RCE can only capture in non-promiscuous mode.
  • The LiveWire RCE can only connect with 1 LiveWire control point.
  • You cannot log into the LiveWire UI on a LiveWire RCE. You can only perform actions and configure the LiveWire RCE through the LiveWire control point.
    Note: The REST API is still accessible on the LiveWire RCE.

Grid

  • Grid does not support LiveWire RCE
  • LiveWire RCEs will not be included in a LiveWire control point's engines list, which is synchronized between Grid and the LiveWire control point.

Omnipeek Windows

  • Omnipeek Windows cannot be used as a LiveWire control point for LiveWire RCE, and cannot connect to a LiveWire RCE.