<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Metron: ingest PCAP files in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Metron-ingest-PCAP-files/m-p/188353#M68118</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I saw that it's possible to use pycapa script in order to capture data and send it to kafka.&lt;BR /&gt;Do you know if there's an easy way to directly ingest pcap file that has been generated by another system? Like a program that read the pcap file and send it to kafka? Or another manner to do it?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Michel&lt;/P&gt;</description>
    <pubDate>Fri, 15 Sep 2017 20:20:45 GMT</pubDate>
    <dc:creator>msumbul1</dc:creator>
    <dc:date>2017-09-15T20:20:45Z</dc:date>
    <item>
      <title>Metron: ingest PCAP files</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Metron-ingest-PCAP-files/m-p/188353#M68118</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I saw that it's possible to use pycapa script in order to capture data and send it to kafka.&lt;BR /&gt;Do you know if there's an easy way to directly ingest pcap file that has been generated by another system? Like a program that read the pcap file and send it to kafka? Or another manner to do it?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Michel&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 20:20:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Metron-ingest-PCAP-files/m-p/188353#M68118</guid>
      <dc:creator>msumbul1</dc:creator>
      <dc:date>2017-09-15T20:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: Metron: ingest PCAP files</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Metron-ingest-PCAP-files/m-p/188354#M68119</link>
      <description>&lt;P&gt;Yes, we do that a lot for testing.  &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;First, use a tool like 'tcpreplay' to replay a pcap file to a network interface.  There is even a simple tool in Metron (https://github.com/apache/metron/tree/master/metron-deployment/roles/pcap_replay) that effectively wraps 'tcpreplay' to make it easy to replay packet captures to a virtual network interface.  &lt;/LI&gt;&lt;LI&gt;Then use 'pycapa' in producer mode to sniff the packets from that network interface and land them in Kafka.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Sun, 17 Sep 2017 02:19:14 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Metron-ingest-PCAP-files/m-p/188354#M68119</guid>
      <dc:creator>nallen</dc:creator>
      <dc:date>2017-09-17T02:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Metron: ingest PCAP files</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Metron-ingest-PCAP-files/m-p/188355#M68120</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/3642/nallen.html" nodeid="3642"&gt;@nallen&lt;/A&gt; &lt;/P&gt;&lt;P&gt;The pcap_replay is install as a service by default with HCP 1.2? If not, how to install it manually?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 14:44:28 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Metron-ingest-PCAP-files/m-p/188355#M68120</guid>
      <dc:creator>msumbul1</dc:creator>
      <dc:date>2017-09-21T14:44:28Z</dc:date>
    </item>
  </channel>
</rss>

