This URL updates the packet capture settings.
Resource URL
PUT /sensor/<sensor_id>/packetcapture
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Sensor id | Number | Yes |
Payload Request Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Packet capture settings can be: monitoring SPAN port/manager/scp server | Object | No |
| List of template names | StringList | No |
| List of rules | ObjectList | No |
Details of capTureSettings:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Monitoring SPAN port details | Object | No |
| Manager settings | Object | No |
| SCP server settings | Object | No |
Details of monitoringSPANPort:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Monitoring SPAN port | String | No |
| Duration details | Object | Yes |
Details of captureDuration:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Capture duration | Number | No |
| Run until released | Boolean | Yes |
Details of Manager:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Capture size | Number | Yes |
Details of scp Server:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| IP of SCP server | String | Yes |
| SCP user name | String | Yes |
| SCP server password | String | Yes |
| Capture size | Number | Yes |
Details of object in rules:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Rule id given if updating existing rule | Number | No |
| Monitoring port. Give ALL if choosing for all ports | String | Yes |
| Traffic. Can be ALL/ARP/IP | String | Yes |
| Protocol. Can be TCP/UDP/ICMP/PROTOCOL_NUMBER | String | Yes |
| IP version. Can be IPV_4/IPV_6 | String | Yes |
| Fragments only | Boolean | Yes |
| Source IP | String | No |
| Source mask | Number | No |
| Source port | Number | No |
| Destination IP | String | No |
| Destination mask | Number | No |
| Destination port | Number | No |
| VLAN id | Number | No |
| Protocol number | Number | No |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Status returned | Number |
Example
Request
PUT https://<NSM_IP>/sdkapi/sensor/1001/packetcapture
Payload
{
"capTureSettings": {
"monitoringSPANPort": {
"port": "ALL",
"captureDuration": {
"captureDurationInMinutes": 0,
"runTillExplicitlyReleased": true
}
},
"manager": null,
"scpServer": null
},
"templates": ["test",
"test1"],
"rules": [{
"ruleId": 2,
"monitoringPort": "ALL",
"traffic": "ARP",
"protocol": "TCP",
"ipVersion": "IPV_4",
"fragmentsOnly": true,
"sourceIP": "0.0.0.0",
"sourceMask": 0,
"sourcePort": 0,
"destinationIP": "0.0.0.0",
"destinationMask": 0,
"destinationPort": 0,
"vlanId": 0,
"protocolNumber": 0
},
{
"ruleId": 3,
"monitoringPort": "ALL",
"traffic": "IP",
"protocol": "ICMP",
"ipVersion": "IPV_4",
"fragmentsOnly": false,
"sourceIP": "192.168.12.0",
"sourceMask": 23,
"sourcePort": 1,
"destinationIP": "192.168.12.0",
"destinationMask": 23,
"destinationPort": 1,
"vlanId": 1,
"protocolNumber": 0
},
{
"ruleId": null,
"monitoringPort": "ALL",
"traffic": "ALL",
"protocol": "TCP",
"ipVersion": "IPV_4",
"fragmentsOnly": false,
"sourceIP": "0.0.0.0",
"sourceMask": 0,
"sourcePort": 0,
"destinationIP": "0.0.0.0",
"destinationMask": 0,
"destinationPort": 0,
"vlanId": 0,
"protocolNumber": 0
}]
}
Response
{
"status": 1
}
Error Information
Following error codes are returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 404 | 1106 | Invalid Sensor |
2 | 500 | 1124 | The Sensor is inactive |
3 | 400 | 6201 | Packet capture not supported on this Sensor |
4 | 400 | 6202 | Packet capture duration should be between 1 and 9999 |
5 | 400 | 6203 | Packet capture size should be between 1 and <maxsize> |
6 | 400 | 6204 | SCP server IP, username, password, and capture size are mandatory |
7 | 400 | 6205 | SCP server username should not contain space and special characters other than {-,_,.} |
8 | 400 | 6206 | File upload in progress so could not save the configuration now |
9 | 400 | 6209 | No template present for packet capturing --> <template_name> |
10 | 400 | 6210 | Protocol number should be between 1 and 65535 when PROTOCOL_NUMBER is selected as protocol while you have given --> <protocol_number> |
11 | 400 | 6211 | The rule id give to update is incorrect |