articles:livevspcap
Differences
This shows you the differences between two versions of the page.
Next revisionBoth sides next revision | |||
articles:livevspcap [2017/11/15 18:35] – created veera | articles:livevspcap [2017/11/15 18:53] – [Issue 1 : The Clock] veera | ||
---|---|---|---|
Line 14: | Line 14: | ||
In Live traffic capture, the wall time is the clock. During low traffic periods your CPU and Memory usage goes down, but the rate of time is fixed. | In Live traffic capture, the wall time is the clock. During low traffic periods your CPU and Memory usage goes down, but the rate of time is fixed. | ||
- | When you read PCAPs, most tools are clocked on the timestamp present in the PCAP file, not on the wall clock. | + | When you read PCAPs, most tools are clocked on the timestamp present in each packet inside |
+ | - If Event-B and Event-A that occurred at the same time in real world, arrive at the backend 40 minutes apart. Can they be stored and indexed correctly ? | ||
+ | - If Event-B generates some new enrichment data about Event-A and they arrive 40 minutes late at the backend. What happens to the enrichment? | ||
- | * A single |
articles/livevspcap.txt · Last modified: 2017/11/15 23:27 by veera