Packet logs are stored in a raw format in the Manager database. This section provides information on how to convert the packet log data into PCAP format.
There are two types of packet logs stored in the table. One is regular packets and other one is fragment packets. Packet logs are applicable only to signature alerts (that is, alert of alertType = 1). For a given UUID, we may have both regular and fragment packet logs. So, the PCAP will have a file header and one or more packet headers for both regular and fragment packet logs.
Note
The Manager does provide packet logs in the order of creationTime. So, creationTime is not unique, and the microseconds in appended based on the packet log sequence numbers in the PCAP.
The high-level steps involved in creating PCAP for packet logs based on a UUID are provided below.
Retrieve an alert data for the given UUID, from the iv_alert.
Use an SQL query to retrieve the alert data. For example, if UUID is 12890,
Select * from iv_alert where UUID = 12890
Retrieve both regular and fragment packet logs data using the SensorId and the packetLog id in the alert data, from the iv_packetlog.
Use an SQL query to retrieve all regular packets with the SensorId and the packetLogId. Example: For Sensorid = 101 and packetlog id = 2002, the following is the query to get the regular packets from the iv_packetlog:
Select * from iv_packetlog WHERE SensorId = 101 AND packetLogId = 2002 AND packetLogType = ‘P’ ORDER BY SensorId, packetLogId, packetLogType, packetLogSeq, lastReqByteStreamOffset, lastRespByteStreamOffset";Use an SQL query to retrieve all fragment packets:
Select * from iv_packetlog WHERE SensorId = 101 AND packetLogId = 2002 AND packetLogType = ‘F’ ORDER BY SensorId, packetLogId, packetLogType, packetLogSeq, lastReqByteStreamOffset, lastRespByteStreamOffset";
Create the pcap file header and write them into a file. The PCAP file header format is described below.
Create the pcap packet headers for all regular packets and write them into the file.
Create the pcap packet headers for all fragment packets and write them into the file.
Use the file with Wireshark.
More information regarding steps 3, 4, and 5 are provided in the subsequent sections.