LiveWire Engines view - User Guide - LiveWire - 26.2.0

LiveWire User Guide

ft:locale
en-US
Product name
LiveWire
Version
26.2.0

The Engines view displays information about LiveWire engines that have been added to LiveWire.

To navigate to the LiveWire Engines view, select the hamburger menu and select the arrow button next to Engines. The Engines View page opens.



The Engines table displays a list of all LiveWire engines, including group engines, non-group Engines, and LiveWire RCEs, that have been added to this LiveWire.

Note: Non-group engines are visible and configurable only by users that added them to the LiveWire.

Using the Engines toolbar

The toolbar above the Engines table provides the following options for managing LiveWire engines:
  • Insert: Adds a new LiveWire engine to the Engines view. For more information, refer to Adding LiveWire engines to the Engines View.
  • Edit: Edits the selected LiveWire engine. This option is only enabled when you select the checkbox next to a single LiveWire engine in the table. For more information, refer to Editing LiveWire engines from the Engines View.
  • Delete: Deletes the selected LiveWire engine(s). This option is only enabled when you select the checkbox next to one or more LiveWire engines in the table. For more information, refer to Deleting LiveWire engines from the Engines View.
  • Synchronize: Synchronizes an updated Authentication Group Secret to all group engines and LiveWire RCEs. For more information, refer to Synchronizing group engines.
  • Import (upload icon): Imports LiveWire engines from an Engines.omc file into the Engines view. For more information, refer to Importing LiveWire engines.
  • Export (download icon): Exports the selected LiveWire engines to an Engines.omc file. This option is only enabled when you select the checkbox next to one or more LiveWire engines in the table. For more information, refer to Exporting LiveWire engines.

Select the Refresh icon to manually refresh the list of LiveWire engines, or configure the page to automatically refresh after 1 minute, 2 minutes, 5 minutes, 10 minutes, 30 minutes, or 1 hour.

If you have a large number of LiveWire engines, you can use the page size and navigation at the bottom of the table to paginate between sets of LiveWire engines.

Select the checkbox next to the LiveWire engine name in the table to edit or delete engines. Additionally, you can select or deselect multiple LiveWire engines in the table by selecting in the engine table header and selecting one of the following options:
  • Deselect all: Deselects all LiveWire engines that were selected.
  • Deselect all in page: Deselects all LiveWire engines that were selected on the current page.
  • Select all in page: Selects all LiveWire engines that are displayed on the current page.

You can also perform specific actions on individual LiveWires by selecting in the row of the LiveWire and selecting an action. For more information, refer to Performing LiveWire engine actions from the LiveWire Engines view.

Navigating using the LiveWire Engines table column values

In some data columns, you can select the value within that column to navigate to relevant LiveWire engine pages that display detailed information. The following columns contain clickable values and navigate you to the relevant pages:
Attention: None of the following values are clickable for LiveWire RCEs.
  • Name: Clicking this navigates you the Engine Home View for that LiveWire. For more information, refer to Home view.
  • Captures: Clicking this navigates you to the Captures View for that LiveWire. For more information, refer to Captures view.
  • Capture Sessions: Clicking this navigates you to the Forensics View for that LiveWire. For more information, refer to Forensics view.
    Note: You must have the View Forensics ACL privilege.
  • Files: Clicking this navigates you to the Files View for that LiveWire. For more information, refer to Files view.
  • Forensic Searches: Clicking this navigates you to the Forensic Searches View for that LiveWire. For more information, refer to Forensic searches view.
    Note: You must have the View Forensic Searches ACL privilege.
  • Events (Informational): Clicking this navigates you to the Events View for that LiveWire filtered on Informational events. For more information, refer to Events view.
  • Events (Major): Clicking this navigates you to the Events View for that LiveWire filtered on Major events. For more information, refer to Events view.
  • Events (Severe): Clicking this navigates you to the Events View for that LiveWire filtered on Severe events. For more information, refer to Events view.
  • Events (Total): Clicking this navigates you to the Events View for that LiveWire filtered on Total events. For more information, refer to Events view.
  • Audit Logs: Clicking this navigates you to the Audit Log View for that LiveWire. For more information, refer to Viewing audit log data.
    Note: You must have the Configure Engine and View Audit Log ACL privileges.
  • Connected Users: Clicking this navigates you to the Connected Users View for that LiveWire. For more information, refer to Viewing connected users.
    Note: You must have the Configure Engine and View Connected Users ACL privileges.

Filtering LiveWire engines

Each column header in the LiveWire Engines table has a filter icon that allows you to filter LiveWire engines that are displayed within the table. Select the filter icon within the column to filter the LiveWire list.

The types of filters that can be applied depend on the field that you are filtering on. The filter types are as follows:
Filter type Filter controls
String filters
  • Contains
  • Does not contain
  • Equals
  • Does not equal
  • Begins with
  • Ends with
  • Blank
  • Not blank
Number filters
  • Equals
  • Does not equal
  • Greater than
  • Greater than or equal to
  • Less than
  • Less than or equal to
  • Between
  • Blank
  • Not blank
Date/Time filters
  • Less than
  • Greater than
  • Before
  • After
  • Between
  • Blank
  • Not blank
Last Contact filters
  • Within last
  • Older than
Note: Most filters include an option to add multiple clauses, connected with AND/OR logic. This is presented after an initial filter clause is added.

When a filter is applied, a blue dot appears next to the filter icon to indicate that the table content is filtered.

You can remove a filter by deleting all input from each filter icon dropdown, or by selecting in the engine table header and selecting Clear filters to clear all filters from all columns of the table.

Important: Filters persist if you navigate away from the Engines view and return to the Engines view.

Customizing the LiveWire Engines table

By default, the LiveWire Engines table displays the following columns with information about the LiveWire engines:
  • Name
    Note: The host LiveWire engine displays a star next to its capture engine name.
  • Group
  • Host
  • Version
  • Host name
  • Uptime
  • Capture storage
  • Captures
  • Captures status
  • Packets received
  • Packets filtered
  • Files
  • Forensic searches
  • Events (minor)
  • Events (major)
  • Events (severe)
  • Events (total)
  • Last contact

    The Last contact column displays the heartbeat status of the individual LiveWire engines. A green heartbeat status icon indicates that the group engine has communicated within the last 1 hour. If the LiveWire engine has not communicated within the last 1 hour, a red heartbeat status icon appears.

    The threshold of the heartbeat status can be configured through the LiveWire preferences.

Click the name of a column to sort the column values in ascending or descending order. When a column's content is sorted, an arrow appears next to the column name to indicate the sorting of the values.

You can adjust the width of the columns by selecting the edge of the column and adjusting the slider to increase or decrease the column width.

You can also adjust the ordering of columns by selecting the column and dragging the column to the left or right within the table.

To add or remove columns from the LiveWire Engines table, select in the engine table header and select the column values that you would like to display in the table or remove from the table.

Additionally, you can select one of the following options to customize the table columns:
  • Default columns: Resets the table to display the default columns.
  • All columns: Adds all available columns to the table.
  • Fit columns: Adjusts the width of all visible columns so that they fit within the current size of the table.
  • Reset columns: Restores the default column sorting, size, and ordering of columns in the table.
Important: Column customizations persist if you navigate away from the Engines view and return to the Engines view.