Sign inSign up

gravwell/network_capture

By gravwell

•Updated 25 days ago

Gravwell Raw PCAP capture ingester bundled into a Docker Image

Image
0

5.6K

gravwell/network_capture repository overview

Refer to Gravwell's Docker guide⁠ information on how to deploy ingester containers.

Note: The NetworkCapture ingester requires a Linux host.

The network_capture image is designed to be fed the listening interface, capture snap length, and an optional BPF filter using environment variables. The listening interface is controlled using an environment variable named GRAVWELL_SNIFF_INTERFACE. If no GRAVWELL_SNIFF_INTERFACE environment variable is found, it defaults to listening on on the first non-loopback interface that is up. An optional BPF filter can be specified using the GRAVWELL_SNIFF_BPF_FILTER environment variable. The capture snap length can be controlled using the environment variable GRAVWELL_SNIFF_SNAPLEN.

If no BPF filter is provided, a default filter of not tcp port 4023 and not tcp port 4024 is used so that captured traffic is not recaptured in the ingest link.

Here is an example docker run invocation.

The example will start a the NetworkCapture container that is monitoring the host interface eno1 and ignoring all traffic on TCP ports 443, 4023, and 4024. The Gravwell ingester is configured to send data to 2 indexers at 192.168.1.1 and 192.168.1.2 using the secret IngestSecrets. We will also only capture the first 512 bytes of each packet.

docker run -d --name sniffer --net host \
    -e GRAVWELL_CLEARTEXT_TARGETS="192.168.1.1,192.168.1.2" \
    -e GRAVWELL_INGEST_SECRET="IngestSecrets" \
    -e GRAVWELL_SNIFF_INTERFACE="eno1" \
    -e GRAVWELL_SNIFF_BPF_FILTER="not tcp port 443 and not tcp port 4023 and not tcp port 4024" \
    -e GRAVWELL_SNIFF_SNAPLEN=0x200 \
    gravwell/network_capture:latest

Checkout https://docs.gravwell.io/search/packet/packet.html⁠ for information on the Gravwell packet search module and additional information about processing raw network packets once you have begun ingesting.

Tag summary

Content type

Image

Digest

sha256:97d2fa1bf…

Size

21.6 MB

Last updated

25 days ago

docker pull gravwell/network_capture