Network Monitor fails to process captured packets .vpcap files.

book

Article ID: 160767

calendar_today

Updated On:

Products

Data Loss Prevention Network Monitor

Issue/Introduction

On Network Monitor you observe excessive restart of Filereader, however PacketCapture keeps running and creating .vpcap files under drop_pcap folder. No increase in message count or no incident from Network Monitor.

Resolution

This is very common issue when some bad traffic chocks the filereader process and further inspection/detection would stop. As a result filereader of Network Monitor keeps restarting until we manually remove the bad traffic file. Please follow the below steps to overcome this issue.

1. In this situation drop_pcap folder keeps filling up with .vpcap files under directories have numerical name.

2. We need to manually stop PacketCapture service of Network Monitor from UI console.

3. Once PacketCapture stops you will not get new packet capture file.

4. Move all files/directory from drop_pcap folder to some temporary location. Here you will also find error to move some directories which are locked/used by process. These directories/files are culprit for this issue.

5. To unlock these directories, you need to stop VontuMonitor service on Network Monitor server and either move or delete these directories from drop_pcap. Don't move them to the location where you have all other directories/files. Move them to separate location.

6. Start VontuMonitor service again from server. Restore old files/directories back to drop_pcap folder in bunch.

7. Ensure that you will see increase in message count from UI console for this network monitor server.

8. If above steps doesn’t work then you need to log a case as there are other possible causes also for similar situation.