Performing LiveWire engine actions from the LiveWire Engines view - User Guide - LiveWire - 26.2.0

LiveWire User Guide

ft:locale
en-US
Product name
LiveWire
Version
26.2.0

From the LiveWire Engines view, you can perform actions on LiveWires by selecting in the row of the LiveWire. Depending on whether the LiveWire is a non-RCE LiveWire or a LiveWire RCE, the actions that can be performed differ.

Non-RCE LiveWire actions

For non-RCE LiveWire engines within the table, you can perform the following actions by selecting in the row of the non-RCE LiveWire:
  • Refresh: Retrieves the latest information from that LiveWire.
    Note: This option is only visible for LiveWire group engines running software version 26.2 or greater.
  • View engine: Redirects you to the Engine Home View for that LiveWire. For more information, refer to Home view.
  • Configure engine: Redirects you to the Engine Configuration View for that LiveWire. For more information, refer to Configuring the Capture Engine.
    Note: You must have the Configure Engine ACL privilege.
  • Configure system: Redirects you to the LiveAdmin page for that LiveWire. For more information, refer to Using the LiveAdmin utility.
    Note: This is only available to LiveWire deployed on Linux.
  • Update license or Renew license: Redirects you to the Activation View for that LiveWire.
  • View audit log: Redirects you to the Audit Log View for that LiveWire. For more information, refer to Viewing audit log data.
    Note: You must have Configure Engine and View Audit Log ACL privileges.
  • View captures: Redirects you to the Captures View for that LiveWire. For more information, refer to Captures view.
  • View connected users: Redirects you to the Connected Users View for that LiveWire. For more information, refer to Viewing connected users.
    Note: You must have the Configure Engine and View Connected Users ACL privileges.
  • View events: Redirects you to the Events View for that LiveWire. For more information, refer to Events view.
  • View files: Redirects you to the Files View for that LiveWire. For more information, refer to Files view.
  • View forensics: Redirects you to the Forensics View for that LiveWire. For more information, refer to Forensics view.
    Note: You must have the View Forensics ACL privilege.
  • View forensic searches: Redirects you to the Forensic Searches View for that LiveWire. For more information, refer to Forensic searches view.
    Note: You must have the View Forensic Searches ACL privilege.
  • View settings: Redirects you to the Settings View for that LiveWire. For more information, refer to Settings view.
  • View support: Redirects you to the Support View for that LiveWire. For more information, refer to Viewing and downloading support information.
    Note: You must have the Configure Engine ACL privilege.

LiveWire RCE actions

If you are running LiveWire RCE version 26.1 or earlier, you cannot perform actions on the LiveWire RCE and the option will not be available.

For LiveWire RCEs running software version 26.2 or later within the table, you can perform the following actions by selecting in the row of the LiveWire RCE:
  • Refresh: Retrieves the latest information from that LiveWire.
  • Start capture or Start trigger: Starts the capture on the LiveWire RCE.
    Note: The action is performed only if you have the Start Stop Captures ACL privilege, there are no copy or move operations in progress, and the capture is not running.
  • Stop capture or Abort trigger: Stops the capture on the LiveWire RCE.
    Note: The action is only performed if you have the Start Stop Captures ACL privilege and the capture is running or waiting for a trigger.
  • Capture options: Opens the Capture options modal dialog that allows you to configure the capture on the LiveWire RCE. For more information, refer to Updating the default capture on the LiveWire RCE.
    Note: You must have the Modify Captures ACL privilege.
  • Copy files: Opens the Copy files modal dialog that allows you to copy files from the LiveWire RCE. For more information, refer to Copying capture files from an RCE to the LiveWire control point.
    Note: This action can only be performed if the capture on the LiveWire RCE is not running, you have the Download Files ACL privilege, there is not a file transfer already in progress, and there is at least 1 packet file that can be copied.
  • Move Files: Opens the Move files modal dialog that allows you to move files from the LiveWire RCE. For more information, refer to Moving capture files from an RCE to the LiveWire control point.
    Note: This action can only be performed if the capture on the LiveWire RCE is not running, you have the Delete Files and Download Files ACL privileges, there is not a file transfer already in progress, and there is at least 1 packet file that can be moved.
  • Delete all files: Opens the Delete files modal dialog that allows you to delete all capture files on the LiveWire RCE. For more information, refer to Deleting capture files from an RCE.
    Note: You can only delete files if the capture on the LiveWire RCE is not running, there is no copy or move operation in progress, and you have the Delete Files ACL privilege.