Decoder: (Optional) Configure a Decoder to Write Standard pcap-formatted Files

Document created by RSA Information Design and Development on Sep 11, 2018Last modified by RSA Information Design and Development on Apr 10, 2019
Version 2Show Document
  • View in full screen mode

Note: The information in this topic applies to RSA NetWitness® Platform Version 11.2 and later.

To provide a more open database format, the Network Decoder can now write standard pcap-formatted files. You can enable pcapng-formatted database files with the new configuration node:
/database/config/packet.file.type = 'netwitness' or 'pcapng'

Note: This capability is enabled by default if you install 11.2 directly. If you upgrade from a previous version to 11.2, you must enable pcapng-formatted database files manually, which can result in an approximate 4% decrease in disk space (as the pcapng files require more space than the nwdb files). You can also use the pcapng format with 10 Gbps capture, which does not decrease performance significantly (< 1%).

To enable writing standard pcap-formatted files:

  1. Go to ADMIN > Services, select a Network Decoder service, and then select The actions menuView > Explore.
  2. Go to database > config.
  3. In packet.file.type, the default is netwitness.
  4. To change the packet file type to standard pcap formatting, type pcapng and press Enter. This change will take effect immediately on the next packet file that is created.

Note: In the pcapng database file format, the data is in clear text, and is not obfuscated by our proprietary format, which can improve security.

Caution: Please do not touch any files in the packet database directories! You must not read or edit any pcapng file in the packet database directories, as they are always in use while Decoder is running. Decoder always expects full and exclusive access to those files, and other processes reading those files prevent normal Decoder operation. The proper way to access the pcapng files is to set up a cold storage directory. This allows Decoder to copy pcapng files to the cold storage directory before deletion. At that point, you are responsible for managing the pcapng files, including making sure that the cold storage volume never fills up. Keep in mind that copying the pcapng files to cold storage requires a non-trivial amount of I/O and could interfere with packet capture. Cold storage for pcapng is not supported at 10G speeds.

You are here
Table of Contents > Configure Common Settings on a Decoder > Configure Capture Settings > Decoder: (Optional) Configure a Decoder to Write Standard pcap-formatted Files