Once a LiveWire RCE has been installed and successfully connects to the LiveWire control point, the LiveWire RCE appears in the LiveWire control point's engine list. For more information, refer to LiveWire Engines view.
LiveWire RCE comes with a default capture that is started upon installation. The capture,
named RCE Capture, is configured with the following capture options:
- The capture to disk (CTD) File Size is set to 1 GB.
- The capture to disk reserve space supports up to 10 capture files, or
fewer if the amount of disk space is smaller.Note: The LiveWire RCE fails to start if, while initially creating the default capture, it cannot secure space for at least 1 capture file.
- The default adapter is automatically selected. The first physical ethernet adapter is selected.
Attention: Any captures that might have previously existed
will be ignored. This may occur in the following scenarios:
- You had a LiveWire RCE running software version 26.1 or earlier and you upgraded to 26.2 or later.
- You switched from a non-RCE LiveWire to a LiveWire RCE.
To update the capture options and begin analyzing packets from the RCE, perform the
following steps:
- If you would like to update the default capture options, navigate to the Engines list on the LiveWire control point and update the capture on the LiveWire RCE. For more information, refer to Updating the default capture on the LiveWire RCE.
- Once the capture collects packets, move or copy the files from the RCE to the LiveWire control point. For more information, refer to Moving capture files from an RCE to the LiveWire control point and Copying capture files from an RCE to the LiveWire control point.
- Perform analysis on files from the LiveWire control point. For more information, refer to Performing a Forensic Search on capture files.