I'm wondering if anyone on this board has experience to recommend (or not) a dedicated packet capture appliance. The goal would be to separate the idea of packet analysers/probes from the time-sensitive capture process itself, such that mirrors or a tap network would feed a central "packet capture appliance", and that system would make resulting packet capture files available to remote servers for analysis (be it wireshark, snort, etc.). A short list of things that such a system would need to do well:
While an off-the-shelf server can do most of this, I also know that a few vendors have dedicated appliances tailored to some of these kinds of capture-specific requirements. So, my overall question here is, do people here have any good/bad experience to share about such appliances? In such a niche space, are there any that particularly stand out? Realizing it isn't directly a Wireshark tool question, I'm not sure if there is a better place where such a question would be asked. asked 24 Feb '16, 14:38 Quadratic |
One Answer:
I can recommend the NetShark appliances (hardware as well as virtual) from Riverbed. answered 25 Feb '16, 01:35 Uli |
if you send me an email creusch[at]crnetworks.de I can provide you my experience