DocsPlatform administration

Control administration

Administer identity, networking, time, monitoring, storage protection, and Capuris platform services.

Capuris Control provides the system settings behind packet capture and retention. Make one administrative change at a time, record the previous value, and verify the affected workflow before closing the change.

Sign in securely

Open Capuris Control on the approved management address and authenticate with a named account. Avoid shared administrator credentials. Sign out when the session is complete, especially on a shared workstation.

If authentication fails, verify the target hostname, account source, account status, time synchronization, and the health of any LDAP or TACACS+ dependency. Do not repeatedly test a password if the identity system enforces lockout.

Configure management networking

The network pages define how the appliance reaches administrators, DNS, time sources, analytics, backups, and remote storage.

  1. Record the existing interface addresses, routes, and gateway.
  2. Confirm the new address, prefix, VLAN, and routing design.
  3. Apply the interface change from a session that has a recovery path, such as BMC or console access.
  4. Reconnect using the new address.
  5. Test the required destinations from the appliance.

Use a default gateway only where the design calls for one. Add a specific route when a remote administrative or storage network should not use the default path. Avoid overlapping subnets and duplicate addresses.

Configure DNS

Set the search domain and name-server addresses supplied by the network team. Save the configuration, refresh the page, and verify both forward and reverse lookups for services the appliance must reach.

When troubleshooting, distinguish a DNS failure from a routing or firewall failure by testing the returned address directly. Use fully qualified names for infrastructure dependencies when search-domain behavior could be ambiguous.

Maintain accurate system time

Select the approved NTP, PTP, or hardware timing source. Confirm synchronization after boot and after any network change. Packet timestamps from unsynchronized systems should not be used to calculate one-way delay or order events across observation points.

Document the interface time zone separately from UTC-based logs when they differ.

Manage local users and groups

Create a named account for each operator and grant the least privilege needed for the role. Review account ownership, group membership, and last use on a regular schedule.

To add an account:

  1. Open user management and choose the add action.
  2. Enter the approved user name and identity details.
  3. Assign the required group or role.
  4. Set a temporary credential according to policy.
  5. Save and test the account with a non-destructive action.

Before deleting an account, confirm that it does not own an active automation, scheduled transfer, or operational handoff. Group upload is useful for a controlled bulk change, but review the input and test a small set before a large import.

Connect LDAP

LDAP integration requires a reachable directory service and a clear mapping between directory groups and Capuris roles.

FieldMeaning
ServerDirectory hostname or address
PortLDAP or LDAPS service port
Base DNSearch root for users and groups
Admin Base DNBind identity used for directory queries, when required
Bind passwordSecret for the bind identity
Allowed admin groupsDirectory groups mapped to administrative access
Allowed user groupsDirectory groups mapped to standard access

Test the connection before enabling the provider. Use TLS and certificate validation where supported. Keep one tested local recovery account in case the external directory is unavailable. When disabling LDAP, confirm how existing sessions and directory-only accounts will behave.

Connect TACACS+

Enter a descriptive server name, hostname or address, port, and shared key. Save the server, test authentication with a designated account, and confirm the expected authorization level.

Protect the shared key as a secret. Verify system time, routing, firewall policy, and server reachability before interpreting a rejected login as a bad credential.

Configure Windows namespace access

Windows file access may require a workgroup or Active Directory design. Depending on the selected mode, configure the namespace name, workgroup, realm, password server, WINS server, server description, UID and GID ranges, and an authorized join account.

Use non-overlapping UID and GID ranges. Confirm DNS and time before joining a realm. Do not store a domain administrator credential longer than the operation requires; use a delegated join identity where possible.

Monitor system health

Control exposes hourly, daily, weekly, and monthly views for CPU, memory, network activity, storage capacity, and system load. Select the smallest interval that contains the symptom, then compare it with a known-good period.

SignalWhat to look for
CPUSustained saturation that aligns with capture, search, compression, or transfer work
MemoryPersistent pressure, swap growth, or abrupt change after a release or workload change
NetworkUnexpected throughput, errors, or a silent management interface
StorageCapacity trend, sudden growth, and headroom for rotation or export
LoadWork queued faster than the system can complete it

An isolated spike is context, not a diagnosis. Correlate resource graphs with capture drops, search jobs, transfers, mirrors, and service logs.

Configure alerts

Create alerts for conditions that require an operator response, such as capacity, service state, or resource pressure. Define a threshold, evaluation window, and recipient that avoid repeated noise from harmless short spikes.

After adding or editing an alert, generate a safe test condition or use the product’s test function when available. Verify delivery, timestamp, system identity, and recovery behavior. Deleting an alert removes future detection, so record the approval and replacement control first.

Use graph range, time range, reset, and jump-to-time controls to place an alert in context.

Switch capture adapters

Adapter switching changes the active capture path and can interrupt recording. Stop or schedule the affected capture, record port mappings, apply the switch, then verify link state, packet counters, and a known flow on every active port.

Configure ZR+ optics

On supported hardware, set the optical channel using the approved grid spacing and either frequency in THz or wavelength in nm. Confirm that both ends use compatible values before saving. After the change, verify optical state, link state, error counters, and received traffic.

CAUTION An incorrect optical setting can disrupt a production transport path. Coordinate the value and maintenance window with the optical-network owner.

Protect data with NFS

The NFS data-protection workflow mounts a remote export and transfers selected local capture directories on a schedule.

Connect an export

  1. Enter the NFS host and export path.
  2. Test reachability and list available exports when permitted.
  3. Mount the selected export.
  4. Confirm that status changes to mounted and that a controlled write test succeeds.
  5. Select the local source directories.

Status values commonly distinguish mounted, stale, unreachable, and not connected. A stale mount requires different recovery from an unreachable server; collect mount and network evidence before forcing a change.

Schedule transfers and retention

Choose a daily, weekly, monthly, or one-time schedule, then verify the displayed next run. Save the configuration before enabling scheduled transfers. Use Transfer Now for a controlled test or an urgent copy, not as a substitute for validating the schedule.

Automatic deletion should be enabled only after restore testing proves that remote copies are complete and usable. Set the retention period and deletion time from an approved policy. Pending transfer jobs remain separate from deletion activity.

Review NFS evidence

Use disk usage, NFS statistics, connection diagnostics, mount logs, transfer logs, deletion logs, and pending jobs to identify the failing stage. Clear logs only after preserving the entries required for support or audit.

The NFS server must export the expected path to the appliance client network with appropriate permissions. Validate server export options, SELinux policy, and firewall rules with the storage owner.

Configure local snapshots

Select the file spaces that need point-in-time protection, then define hourly, nightly, or monthly schedules and the number of copies to retain. Estimate the capacity impact before enabling the policy. After the first run, confirm that a snapshot exists and perform a controlled restore test.

Snapshots do not replace an off-system backup. A failure that affects the appliance or its storage can affect local snapshots as well.

Mirror snapshots to a remote host

Snapshot Mirror copies selected local directories to configured remote host slots.

  1. Choose a host slot and enter a clear label.
  2. Configure the remote hostname or address and approved SSH credential.
  3. Select the vendor-system or other Unix/Linux system profile.
  4. Set the remote path and review the destination preview.
  5. Choose the local source directory.
  6. Select hourly, nightly, or monthly frequency and the start time.
  7. Choose mirror or archive behavior.
  8. Create the remote directory with the provided control when needed.
  9. Run the connection diagnostic.
  10. Save, enable, and perform a manual test with Mirror Now.

Mirror mode makes the destination follow the source and may remove remote files that no longer exist locally. Archive mode retains historical material according to its design. Confirm the intended semantics before the first production run.

The status page shows configuration, scripts, remote target, schedule, and running processes. If a job is stuck, collect the rsync log and process state before using Stop Mirror. Disable removes scheduled mirror jobs and generated scripts while retaining host configuration; verify the release behavior before relying on that distinction.

Configure full remote mirror

Full Remote Mirror protects selected file spaces on another system. Enter the host name, address, credential, system type, file spaces, and timing. Because the data volume can be substantial, validate available bandwidth, destination capacity, transfer duration, and capture impact with a representative test.

Disable the job before changing the destination or source set. Confirm the most recent successful transfer and restore path before treating the mirror as a recovery copy.

Transfer files with NFS

For a direct NFS file-transfer profile, configure the host name, address, NFS export, local mount directory, selected subdirectories, schedule type, and run time. Save before enabling. Use Reset only to return unsaved fields to the current configuration; do not assume it removes remote data.

Update software

Plan software updates as a controlled change:

  1. Read the release notes and confirm model, version, and license compatibility.
  2. Back up configuration and verify the current data-protection state.
  3. Record service health, capacity, capture state, and active jobs.
  4. Stop or reschedule work that the update cannot safely interrupt.
  5. Upload or stage the approved package and verify its checksum.
  6. Start the update and keep console or BMC access available.
  7. Do not power off the system while the package is being applied.
  8. After restart, verify version, services, users, networking, time, storage, capture, search, and integrations.

If validation fails, preserve update logs and contact support before attempting an unapproved rollback.

For automation, use the Control API reference. For evidence collection, see Support and troubleshooting.