Configure Packet Capture on the ExtraHop Discover Appliance with VMware
This guide describes how to configure the packet capture feature on the EDA 1000v, EDA 2000v, and EDA 6100v virtual ExtraHop Discover appliance with VMware. When packet capture is enabled through the Admin UI on the Discover appliance, you can write triggers to specify and deploy targeted packet captures from the Discover appliance to a disk drive on your VMware server.
License packet capture
Ensure that your ExtraHop license has packet capture enabled.
Before you begin
The Discover appliance requires a product key and a license to configure packet capture. Contact ExtraHop Support to obtain your product key.Configure a packet capture disk in VMware
The following settings are configured through the VMware vSphere Web Client.
- Log into the VMware vSphere Web Client.
- Select your Discover appliance virtual machine in the Virtual Machines inventory list.
- From the Actions drop-down list , select Edit Settings.
- From the New device drop-down list, select New Hard Disk, and then click Add.
- Set the size of the disk to 500 GB.
- Expand the New Hard disk settings and confirm that Thick Provision Lazy Zeroed is selected for Disk Provisioning. The remaining disk settings do not need to be changed.
- Click OK.
Enable the packet capture disk
- In the ExtraHop Admin UI, refresh the Disk page. The packet capture disk should display a status of running and the size should display 500.0GB. The drive is now allocated for packet capture.
- In the Actions column for the packet capture disk, next to Triggered Packet Capture, click Enable.
- Click OK to add the packet capture disk.
Configure triggers to define the packet capture
The ExtraHop system gathers custom metrics through Application Inspection Triggers. These metrics are stored internally and can be accessed by the packet capture feature. The system will automatically process packet captures encountered in the trigger script.
Assign trigger to devices
After you create a trigger, the trigger must be assigned to one or more devices before the trigger can begin collecting data.
You also can assign the trigger to a device group, which assigns the trigger to each device in the group.
Warning: | Avoid assigning any trigger to all devices. Running triggers on unnecessary devices exhausts system resources. Minimize performance impact by assigning a trigger only to the specific devices that you need to collect data from. |
- In the ExtraHop Web UI, click Metrics in the top menu, then click in the left pane.
- Select the checkbox for each device you want to assign the trigger to.
- From the Select Action drop-down list, select Assign to Trigger.
- Select the checkbox for the trigger you want to assign to the selected devices.
- Click OK.
View the packet capture results
- In the ExtraHop Admin UI, in the Packet Captures section, click View and Download Packet Captures.
- Select a packet capture and then click Download Selected Captures to download the pcap file to your workstation.
- Open the downloaded packet capture in a packet analyzer, such as Wireshark.
Thank you for your feedback. Can we contact you to ask follow up questions?