Capture and analyze packet data

Extend monitoring and troubleshooting to your most important network segments with scalable, real-time packet analysis

LiveAction LiveWire marketing header describing packet data capture and analysis benefits
Key takeawaysThis key takeaway was generated through LLMs crawling the page and coming up with an overview of the content.

The article describes BlueCat LiveWire, a scalable packet capture and analysis solution designed to restore deep network visibility across data centers, WAN edges, remote sites, and cloud environments. It addresses the operational problem of blind spots and long mean time to resolution (MTTR) caused by distributed architectures and fragmented monitoring tools by providing real-time packet capture, advanced forensic analysis, and conversion of packet data into enriched flow telemetry for LiveNX. Key outcomes include centralized management via LiveWire Grid, scalable hardware and virtual/cloud options (including PowerCore for multi-petabyte retention), faster troubleshooting for applications such as VoIP and video, and improved security incident response through lossless, long-term packet retention and forensic search capabilities.

How does LiveWire improve troubleshooting and reduce MTTR in distributed network environments?

LiveWire improves troubleshooting and reduces MTTR by delivering real-time packet capture and detailed packet-level visibility across critical network segments (data centers, SD-WAN edges, cloud, and remote sites). It provides an easy-to-use interface with advanced visualizations, built-in workflows, and an expert system that guide analysts to root causes. Additionally, LiveWire converts packet data into rich flow data and exports it to LiveNX, enabling rapid transitions between flow-level and forensic-level analysis so teams can quickly identify and resolve application issues such as VoIP and video performance problems without needing multiple disparate tools.

What deployment and scalability options does LiveWire offer to support large and distributed organizations?

LiveWire offers physical, virtual, and cloud appliance options to match different network needs, including small remote offices, large branches, WAN edges, and data centers. Physical appliances range from small Edge devices to high-capacity PowerCore systems, with PowerCore supporting multi-petabyte effective capacity (PowerCore supports 2+ PB raw and 6+ PB effective capacity) and high forensic capture rates. LiveWire Grid provides centralized SaaS-based management for any mix of physical, virtual, or cloud devices, enabling single-console configuration, mass updates, single sign-on, and cloud backup/restore for widely distributed deployments with lower total cost of ownership.

How does LiveWire support security incident response and compliance investigations?

LiveWire supports security incident response by capturing lossless, line-rate packet data that can reveal both the fingerprint and extent of intrusions—information that flow logs alone may not provide. It enables forensic searches across terabytes of stored packet data without disrupting storage systems and provides long-term, scalable retention to meet compliance and protect data integrity. These capabilities allow security teams to perform detailed investigations, produce unequivocal proof of activity, and determine the scope of breaches using the actual packets as definitive evidence.

Network visibility challenges in modern distributed environments

As networks expand from the data center to the WAN edge, remote sites, and cloud, it is increasingly difficult to have visibility across the entire network and quickly troubleshoot networked applications. Most enterprises use a host of network monitoring tools to analyze operational data. But using multiple tools makes issue resolution time-consuming, increasing mean time to resolution (MTTR).

The solution: LiveWire

BlueCat LiveWire is a high-performance packet analysis solution that captures and stores detailed packet data for network and application performance and forensic insights. By deploying LiveWire physical or virtual appliances in your most critical network segments—including data centers, SD-WAN edges, the cloud, and remote sites—your network and security operations teams have the data they need to ensure network performance and security.

LiveWire captures real-time packet data. When you need to examine packets for deep forensic analysis, LiveWire offers an easy-to-use interface, advanced visualizations, built-in workflows, an expert system, and many types of analysis and correlation. LiveWire is built to accelerate troubleshooting and deliver the packet data and packet analysis you need for advanced network forensics.

In addition, LiveWire delivers enriched packet data to BlueCat’s LiveNX network performance management solution. This makes it easy to transition from flow-level to forensic-level analysis and back—all on a single platform. LiveWire converts packet data into rich flow data and automatically exports it to LiveNX. With LiveNX and LiveWire, it’s easy to quickly identify and resolve application issues, such as VoIP and video performance problems, without the need for deep forensic analysis.

Network monitoring dashboard highlighting real-time packet data, network and application performance, and forensic insights

Key capabilities

Digital transformation

Rising machine-to-machine (east-west) traffic in data centers creates costly blind spots. LiveWire delivers:

  • Granular insights to quickly detect and resolve issues across physical and virtual networks.
  • Fast packet capture to identify issues from Layer 2 to 7 for apps, VoIP, and Wi-Fi.
  • Intelligent capture that saves disk space by detecting encrypted traffic and slicing payloads.
  • LiveFlow web analytics with key metrics (URL/URI, response times, error codes) for visibility—even in encrypted traffic.

Ongoing, end-to-end monitoring

Application performance monitoring is critical for keeping your enterprise running smoothly, yet applications are being virtualized and migrated to the cloud at breakneck speed. This creates blind spots, leaving IT organizations dependent on flow logs and APIs for application performance monitoring. LiveWire helps you:

  • Gain a holistic view of network and application events by converting packet data into rich flow-based data using

Enterprise-grade management

IT organizations struggle to find a cost-effective solution that provides visibility across large numbers of branches and remote locations. A solution is needed that can be widely distributed and easily managed, providing true end-to-end visibility. LiveWire offers:

  • Centralized management of LiveWire devices via LiveWire Grid’s web console.
  • Scalable software extending monitoring from data centers to branches and WAN edges.
  • Unified flow and packet capture at any network speed for fast issue resolution.
  • Expandable packet storage—PowerCore supports 2+ PB raw and 6+ PB effective capacity.

Security incident response

When it comes to security incident response, there’s nothing more valuable than the packets themselves. You may have the finest intrusion prevention and detection and/or security event management solution available, but once the intrusion is found, what’s next? You need a recording of the activity—the network packets—to determine both the fingerprint and extent of the breach. With LiveWire, you get:

  • Network packets that reveal both the fingerprint and extent of breaches.
  • Lossless, line-rate capture with scalable hardware and software.
  • Forensic searches on terabytes of data without disrupting storage.
  • Long-term, scalable retention to meet compliance and protect integrity.

Features

Network-wide visibility

Make the highest-quality flow data available from anywhere on your network—especially in your most critical segments—to increase visibility and decrease MTTR. Scalable packet flow data delivers detailed visibility from anywhere across the network, including data centers, the WAN edge, cloud, and remote sites.

Accelerate troubleshooting

Detailed troubleshooting requires detailed data. For network and application troubleshooting, the most detailed data available is the network packets themselves. Workflows and automation drive users to the root cause of network and application issues. The result is increased productivity and fewer solutions (or screens) needed to solve problems.

Security and compliance

Standard security and compliance investigations require the most comprehensive data available—the network packets—to effectively investigate and report on issues, whether for routine reporting, a detailed investigation, or unequivocal proof.

LiveWire Grid

LiveWire Grid is a software as a service (SaaS) solution that simplifies and scales the management and administration of LiveWire devices, no matter how many are deployed. With LiveWire Grid, you get:

  • Single sign-on and improved user experience.
  • Centralized management for physical, virtual, or cloud devices.
  • Simple installation and low total cost of ownership.
  • Single console for configuration and mass updates.
  • Cloud-based backup and restore.

Tuned for your specific needs

LiveWire includes physical, virtual, and cloud offerings, and can be deployed based on your network’s specific needs. LiveWire physical appliances offer massive scalability and performance to support network operations for the largest networks, from branch offices to large data centers to the WAN edge. LiveWire virtual and cloud offerings scale with your needs and deliver the flexibility required in these networking environments.

For organizations with many branch locations, such as banks and retailers, LiveAction offers the LiveWire Edge. The LiveWire Edge is a small-form-factor appliance with no moving parts, making it simple to install and manage. It is perfect for organizations with an already-stretched IT department.

LiveWire Device Specifications

LiveWire deviceEdgeCorePowerCore**Virtual
Use casesSmall or remote officeLarge branch or WAN edgeData centerAll
Network ports4×1G and 1x pass-through4×1G
2×10G
4×10G
4×10G
4×25G
2×40G
2×100G
Configurable
Memory32 GB128 TB256 TBMin. 8 GB
Raw storage1 TB SSD24 TB240 TBConfigurable
Effective storage*N/A72 TB720 TBN/A
LiveFlow exportUp to 1 GbpsUp to 15 GbpsUp to 75 GbpsUp to 4 Gbps
Forensic capture (capture-to-disk)Up to 1 GbpsUp to 40 GbpsUp to 96 GbpsDepends on hardware
Dimensions and weight8.5×5.7×1.7 in
2.64 lbs
1U
39 lbs
2U
73 lbs
N/A
Omnipeek for WindowsYes (1 license)Yes (1 license)Yes (1 license)No

* Assumes a 3:1 data reduction ratio through compression and/or data slicing
** Supports 10 Gbps, 40 Gbps, and 100 Gbps

Next steps

Discover how you can capture and store detailed packet data for network and application performance insights.

BlueCat’s Intelligent Network Operations (NetOps)

BlueCat’s Intelligent NetOps solutions provide the analytics and intelligence needed to enable, optimize, and secure the network to achieve business goals. With an Intelligent NetOps suite, organizations can more easily change and modernize the network as business requirements demand.

Isometric blue UI tiles showing gear, shield, chip, and magnifying glass icons on a grid background