You can configure the session-reconstruction parameters in the pivotengine menu.
Prerequisite: Admin access.
To configure session-reconstruction parameters:
Log in to the NDR as npadmin using the NDR IP address or FQDN. For example:
$ ssh npadmin@10.1.0.1or
$ ssh npadmin@exampleFQDNEnter privileged mode:
npadmin@ia> enableEnter the npadmin password. The password can be 5 to 24 characters long.
[sudo] password for npadmin: <password>Enter configuration mode:
npadmin@ia# configure systemEnter the pivotengine menu:
npadmin@hostname(config) # pivotenginePivotEngine/Session Reconstruction ParametersThumbnail Generation: DisabledAssymetric Flow Stitching: DisabledVLAN Tracking: On-------------------------------------------------------------------
A: Toggle the Asymmetric Stitching of flowsT: Toggle whether to generate thumbnail or notV: Toggle VLAN Tracking for reconstructionQ: Exit and SaveSelect which option you would like to change:Press
Ato toggle the status of asymmetric stitching of flows.By default, "Asymmetric Stitching of flows" is disabled so that the Packet Capture appliance can see bi-directional traffic on each configured capture interface. If your deployment has one capture interface / PX that records the inbound traffic while another capture interface / PX records the outbound traffic, you need to enable this option.
Press
Tto toggle the status of thumbnail generation.When enabled, the Artifacts tab shows thumbnails for extracted artifacts after a successful
session.Press
Vto toggle the status of VLAN Tracking for reconstruction.When enabled, Suricata will look for the same VLAN ID tag in incoming and outgoing flows during session reconstruction. If incoming traffic has a VLAN ID tag and outgoing traffic doesn't have a VLAN ID tag or vice versa, Suricata will not consider it as a session.
Press
Qto save the settings and exit the pivotengine menu.