In the MongoDB, you can see a new database called PCAP files. This is where Packet Capture (PCAP) files are stored. PCAP (also known as libpcap) is an application programming interface (API) that captures live network packet data from OSI model Layers 2-7. In this feature, PCAPs are generated for incident events, available for download, and complete and viable.
Enable Packet Capture (PCAP) in the UI
- Log in to the LogRhythm NDR UI.
- Click the Settings tab, click Policy Management, then click Feature Configuration in the submenu.
- Select the Pcap Enable check box and click Update.
The PCAP service begins storing the PCAP files into the Mongo DB.