Upload Traces

The Upload Traces page lets you upload a trace, or packet capture (pcap) file, that is related to the active organization.

Figure 1. Upload Traces page

Upload Traces page

When a packet capture (pcap) is played for the first time, a Play Context is created automatically. This consists of a:

  • Site
  • Network domain
  • Virtual sensor

When other pcaps are played, they play over the same Play Context until the sensor, or the site, is deleted. In that case, a new context will be generated when playing a file.

The sensor is named Trace Sensor XXX where XXX is a randomized value. This is placed in the sensor list like the others. There is no separation of pcap data versus production data.

For each organization, there can be only be one Trace Sensor. We suggest that you create a separate organization to avoid mixing pcap data with production data.

The Trace Sensor is a real Guardian running in the cloud. Therefore, it goes through the standard synchronization process. For this reason, data will only show in the user interface (UI) after a few seconds.

Use trace timestamp

Select this to keep the original timestamps from the trace logs. This will ensure accurate event timing during analysis.

Replay speed

This dropdown lets you select the playback speed of the trace.

Figure 2. Replay speed dropdown

Replay speed dropdown

Auto play trace after upload

This lets you choose whether or not the trace will automatically play after it has been uploaded. If it is not selected, you have to manually select the icon to the left of the file that you've just uploaded. Alternatively, you can select multiple files to play and select the Play Traces option.

Security Profile

This shows the security level applied to the trace upload.

Columns

The Columns button lets you select which of the available columns for the current page will show.

Refresh

The Refresh icon lets you immediately refresh the current view.

Live

The Live toggle lets you change live view on, or off. When live mode is on, the page will refresh periodically.