Endace
The EndaceProbe Analytics Platform provides 100% accurate, continuous packet capture on network links up to 100Gbps, with unparalleled depth of storage and retrieval performance. Coupled with the Endace InvestigationManager, this provides a central search and data-mining capability across a fabric of EndaceProbes deployed in a network. This integration uses Endace APIs to search, archive and download PCAP file from either a single EndaceProbe or many via the InvestigationManager and enables integration of full historical packet capture into security automation workflows.
- Category
- Network Security
- Pack
- Endace
Configuration parameters
- applianceurl — EndaceProbe URL (e.g. https://<fqdn/ip>[:port]) (required)
- credentials — Username (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- hostname — EndaceProbe System Hostname (required)
Commands (8)
- endace-create-archive — Create an archive task to archive packets of interest on EndaceProbe. Archived packets can later be downloaded from EndaceProbe as a PCAP file. Archived Files never expire. Allowed chars are text, numbers, dash and underscore.
- endace-create-search — Create a search task on EndaceProbe. Search is issued against all Rotation Files on EndaceProbe.
- endace-delete-archive-task — delete archive task
- endace-delete-archived-file — Delete an archived file from EndaceProbe.
- endace-delete-search-task — Delete search task
- endace-download-pcap — Download a copy of the PCAP file from EndaceProbe if PCAP file size is within the threshold value defined by filesizelimit.
- endace-get-archive-status — get status of archived task
- endace-get-search-status — Get search status from EndaceProbe. This command can be polled in a loop until response is received or polling timer is over.