Additional metadata or index fields available in Security Analytics
search cancel

Additional metadata or index fields available in Security Analytics

book

Article ID: 387572

calendar_today

Updated On: 02-07-2025

Products

Security Analytics

Issue/Introduction

There are many indexable or metadata fields which are not indexed by default.  These can be changed in the metadata menus to enhance the searchability of captured packets.

Resolution

You may want to search for http username using Open Parser.  Open Parser has a heavy impact on the capture rate, slowing it down, due to the RAM and CPU resources required. The same data, as well as many others, is available as an index if it is enabled.  

To enable http_auth_username, you will need to login with an admin account and browse to Settings -> Metadata.  In the Web section, look for the HTTP Auth Username field.  Selecting this and saving it will create indexes on any packets captured in the future.  WARNING: The system will reboot once the Save button is selected.

There are many other fields which can be indexed.  If they are all enabled, it would slow the capture rate down due to the RAM and CPU resources required to index each field. The most useful and desirable fields are enabled by default.