
Software Manual 32
Status Tab
3.2.4.3 Traffic Capture
Traffic Capture will use the tool tcpdump to perform network traffic captures and generate a widely compatible .cap file.
A series of rotating capture files will be generated to prevent exhausting local resources and all may be downloaded for
post-capture analysis in the viewer of your choice. Capturing the most relevant information may require trial and error to
obtain the best filter for specific investigations.
Interface: Select which interface is to be used to generate the capture file.
Packet Length: Select which type of packet to be created. The recommended setting for this option is Truncated unless
a deep packet inspection is required.
Truncated: If this option is selected, the packet headers and the first few bytes of the start of the data packet will
be included. Use this option to trace network and connection behavior.
Maximum: If Maximum is selected, the entire packet with its contents will be captured. Use this option to investi-
gate the contents ofthe data exchange, such as Serial IP packets.
Capture (.cap) File Size: Cap files are generated on a rotating basis. This sets the maximum size for each of three indi-
vidual files. The recommended setting for this field is Normal to ensure a minimal amount of system resources are
used.
Normal: 1 Megabyte
Large: 3 Megabytes
Maximum: 1/6 system memory
Filter: Create filters by using the options listed below. The recommended setting for this field is port not 10000.
Mode: Select whether to generate a capture file or viewing live stream of the network traffic.
Comentarios a estos manuales