DocsGet started

Deployment and quick start

Prepare the site, connect the appliance, configure management access, and prove the first capture.

Use this guide to move a new Capuris system from delivery to a verified packet capture. Keep the approved network design, addressing plan, and change record available throughout the installation.

Before the maintenance window

Confirm the following items before the appliance arrives:

AreaRequired decision
PlacementRack location, airflow direction, rail compatibility, and service clearance
PowerSupported input, redundant circuits when required, and a reliable ground
ManagementBMC and operating-system addresses, masks, gateways, DNS, and VLANs
CaptureTAP or SPAN source, interface speeds, optics, breakout, and expected load
TimeNTP, PTP, or 1PPS source and the time zone used in incident records
AccessNamed administrator accounts and the approved authentication method
RetentionCapture directories, storage protection, rotation, backup, and deletion policy

Maintain the ambient temperature specified for the installed model. Do not obstruct intake or exhaust paths. Distribute mechanical load evenly in the rack and connect protective earth before applying power.

Install and cable a physical appliance

  1. Inspect the chassis, rails, adapters, drive carriers, power supplies, and transceivers for damage or missing parts.
  2. Mount the system according to the supplied rail instructions. Use two people or lifting equipment when the chassis weight requires it.
  3. Connect each power supply to the approved circuit.
  4. Connect the BMC port to the out-of-band network.
  5. Connect the management interface to the administrative network.
  6. Connect capture interfaces to the designated TAP, packet broker, or SPAN source. Capture ports are observation interfaces and should not be treated as ordinary management links.
  7. Power on the system and wait for the operating system and capture services to become ready.

CAUTION Do not connect an unapproved capture source to a production network. Incorrect TAP, breakout, or transceiver choices can create link problems outside the appliance.

Establish management access

Retrieve the initial BMC and management addresses from the system console or deployment record. From an administrative workstation, verify that both addresses are reachable on their intended networks.

Open Capuris Control at the management address provided for the deployment. Sign in with the issued administrator account, then replace any temporary credential according to local policy. Configure:

  • management address, subnet mask, and default gateway;
  • DNS search domains and name servers;
  • system hostname and time synchronization;
  • routes required for administration, backup, or analytics;
  • named users, groups, and external authentication when applicable.

After a network change, reconnect with the new address and confirm that the old address no longer answers where that is expected.

Verify time before recording

Accurate timestamps are essential when comparing two capture points or correlating packets with application and security logs.

  1. Select the approved NTP, PTP, or 1PPS source.
  2. Confirm reachability to that source.
  3. Wait for synchronization and check the reported offset or lock state.
  4. Compare the appliance time with a trusted reference.
  5. Record the time zone used by the interface and by exported investigation notes.

Do not use evidence from multiple appliances for timing conclusions until all participating systems have synchronized.

Validate capture interfaces

In Capuris Control, open the capture configuration and review every installed port.

  • Match the logical port number to the physical adapter and connector.
  • Confirm the expected speed and link state.
  • Verify that received packet counters increase when known traffic crosses the monitored link.
  • Check for physical-layer errors or a counter rate that does not match the observation point.
  • Apply an alias that describes the location, direction, or monitored segment.

If the port remains down, confirm the optic type, breakout mode, fiber polarity, speed, FEC expectations, TAP or broker configuration, and the remote link state.

Record a first capture

  1. Choose one validated capture port.
  2. Select a capture directory with enough free capacity.
  3. Use a descriptive file prefix and a short file-rotation interval for the test.
  4. Leave filtering disabled unless the validation plan specifically calls for it.
  5. Start recording and generate known traffic through the monitored path.
  6. Confirm that packet and byte counters increase without reported drops.
  7. Stop the test after a small, reviewable file has been created.

Preserve this initial file until search and export tests are complete.

Prove search and export

Search the test time range for the known source, destination, protocol, or port. Open the result in the packet viewer and verify that timestamps, endpoints, and protocol fields are reasonable. Export a focused PCAP and open it with a standard tool such as Wireshark.

The deployment is not complete until an operator can record traffic, find a known flow, and export a readable file.

Connect Capuris Insight

If the deployment includes Capuris Insight:

  1. Confirm that Insight can resolve and reach the capture appliance.
  2. Register or select the appliance in the analytics interface.
  3. Choose the test capture as input and an approved output location.
  4. Run a small interactive search.
  5. Confirm that nodes, flows, or reports are populated from the test data.

Virtual deployment notes

For Capuris Capture Virtual, reserve CPU, memory, and storage rather than relying on oversubscribed host capacity. Attach management and capture networks to the correct virtual interfaces, and verify that the hypervisor or cloud mirror delivers the expected traffic. Sustained capture performance is determined by the complete path: mirror source, virtual switch, host scheduling, storage throughput, and packet-size distribution.

Begin with a measured test and increase load gradually. A virtual interface reporting a high link speed does not prove that the host can record that rate without loss.

Operational handoff

Before closing the installation task, record:

  • model, serial number, adapters, transceivers, and storage layout;
  • rack, power, BMC, management, and capture-port assignments;
  • software version, hostname, addresses, DNS, routes, and time source;
  • user and external-authentication configuration;
  • tested capture rate, test window, drop counters, and exported PCAP location;
  • retention, backup, alerting, support, and escalation owners.

Next, use Capture and search to configure production recording.