DocsAnalytics and AI

Insight analytics

Search packet-derived data and investigate relationships, flows, alerts, and protocol reports.

Capuris Insight turns packet captures into searchable relationships and reports. A useful investigation starts with a precise question, a short time range, and a known observation point; visualization comes after the evidence scope is defined.

Sign in and choose data

Sign in with a named Insight account. In Interactive Search, select the capture appliance or uploaded dataset that contains the event. Then choose input directories or individual PCAP files and an output location for derived results.

Check file timestamps, size, and capture location before starting. A valid search against the wrong observation point can still produce a convincing but irrelevant graph.

  1. Select the appliance or data source.
  2. Choose a narrow input set.
  3. Define start and end time with the correct time zone.
  4. Add an endpoint, network, protocol, port, or saved filter.
  5. Choose full or sampled processing according to the question.
  6. Start the search and monitor backend status.
  7. Review result counts before interpreting a graph or report.

If backend services fail, preserve the search parameters and error message. Confirm cluster health, output capacity, and worker availability before repeating the same job.

Choose filters and sampling

Insight recognizes a broad protocol set, but useful results depend on traffic visibility and decoder support in the installed release. Begin with endpoint and time constraints, then add protocol filters.

The preselected 100% option analyzes the full chosen input. A 10% option or sampling slider reduces work for exploration but can miss short or rare events. Do not use a sampled result to prove that traffic was absent.

Saved shortcodes or templates make repeated searches consistent. Name them by purpose rather than incident number, review their exact expressions, and version them when behavior changes.

Read the relationship graph

Nodes represent observed entities such as addresses or hosts. Links represent communication derived from the selected packets. Size, color, and line style depend on the active aspect and rule set.

Before drawing a conclusion:

  • confirm the aspect currently displayed;
  • read the legend and node or link rules;
  • check whether DNS resolution changed an address label;
  • inspect packet and byte counts behind the visual weight;
  • open the underlying packet list for decisive relationships.

Different link colors usually reflect a styling rule, category, or state—not automatically an error. Review Graph Properties and Rules to see which condition produced the appearance.

Work with nodes

Depending on the installed release, a single click selects a node, a double click expands or focuses it, and a right click opens additional actions. Tooltips can show addresses, names, protocol activity, counts, and risk annotations.

DNS names are supporting context. They may be stale, shared, or absent, so retain the observed address in investigation notes. Top Talkers provides another place to review resolved labels and traffic volume.

Investigate a potential malicious node

A “Potential Malicious Node” label is an analytic lead, not a final verdict. It may be produced by a rule, reputation source, IDS event, or observed behavior.

  1. Record the rule or alert that marked the node.
  2. Review first and last observed time, peers, ports, protocols, and volume.
  3. Open the integrated packet list for the suspicious relationship.
  4. Compare the behavior with a known-good period or peer group.
  5. Correlate with identity, endpoint, DNS, firewall, and threat-intelligence records.
  6. Export the smallest PCAP that supports escalation or containment.

Analyze flows

Flow Analysis groups related packets so operators can compare conversations rather than individual frames. Use packet or stream minimums to suppress insignificant relationships, but remember that a high threshold can hide scanning or low-volume control traffic.

Review duration, packets, bytes, direction, retransmission clues, and timing. Preview a selected flow before applying new settings to the entire result set. When settings change, record them with the exported finding.

Flow Usage Analysis can display the same data as a list or graph. Use the list for exact ranking and the graph for relationships. Choose the aspect—packets, bytes, peers, protocol, or another available measure—that matches the operational question.

Compare graphs

MultiGraph Compare is useful for before-and-after windows, two sites, or a healthy and degraded sample.

  1. Build two searches with equivalent filters and observation scope.
  2. Open Compare when both results are available.
  3. Use zoom criteria to focus on meaningful relationships.
  4. Identify nodes or links that appeared, disappeared, or changed materially.
  5. Confirm each important difference in the underlying packet or flow data.

Sampling, unequal durations, and different capture points can create apparent differences. Normalize the inputs before treating a visual difference as a network change.

Use alerts

Analytics alerts can surface traffic patterns, thresholds, or query results that need review. Define an alert with a clear owner, severity, and expected response. Test it on controlled data when possible.

IDS Alerts summarize detections derived from the packet set. Review signature, source, destination, time, and packet evidence. Deduplicate repeated events before escalation, and validate high-impact decisions with the original traffic.

Read protocol reports

DNS

DNS reports summarize query and response behavior, result codes, and resolved names where supported. Use them to identify unusual failure rates, new domains, or a resolver that behaves differently from its peers. Confirm the result in packets because retransmissions and capture location can affect counts.

HTTP

HTTP reports may include request and response statistics, methods, content types, hostnames, and status codes for traffic visible to the decoder. Encrypted payload is not available as ordinary HTTP content unless the deployment has an approved method to expose it.

TLS

TLS reports describe observed ports, protocol versions, cipher suites, and server names. These fields help find obsolete negotiation or unexpected destinations, but they do not prove application behavior inside the encrypted session.

TCP round-trip time

TCP RTT reports estimate timing from packet exchanges. Filter to the relevant flow and compare distribution and outliers rather than relying on one average. Capture position, retransmissions, asymmetric routing, and synchronization affect interpretation.

Manage files

File Manager shows data available to Insight. If the list does not update:

  1. confirm the file is in an approved input directory;
  2. wait for transfer completion and a stable file size;
  3. verify permissions and free capacity;
  4. refresh the source or index as supported;
  5. inspect backend and administration logs.

Do not analyze a file that is still being copied or written.

Monitor analytics health

Use Monitoring to correlate search failures or slow processing with node availability, queue depth, CPU, memory, storage, and service state. A large input can be slow without the platform being unhealthy; compare the job size and filter scope with prior runs.

For platform installation and clustering, see Insight administration and deployment. For the source PCAP workflow, see Capture and search.