Skip to content

MÓDULO SPAN.Art

Line-rate packet capture — libpcap → AF_XDP → DPDK → SmartNIC tiers.

Function

Captures bench-side packets at line rate, extracts TLS metadata (JA3/JA4/cipher/SNI/ALPN), cross-correlates with NGFW Syslog records to detect log drops + misclassification. Feeds richest URL source into PURE Discovery Hub (source #6).

See primer for operator-facing intro.

Identity

Element Value
Plane DATA (data-plane capture) — MGMT entry via OOBI
Internal code span-collector
K8s namespace span-art
OOBI slot .230
Capture iface per-bench (sniff target, e.g. mirror port)

5 ingest tiers (pick at install)

Tier Backend Bandwidth
T1 libpcap up to 1 Gbps
T2 AF_XDP 1-10 Gbps
T3 DPDK 10-40 Gbps
T4 SmartNIC offload 40-100 Gbps
T5 external switch SPAN 100+ Gbps

Operator controls

  • /admin/span — ingest tier selector, retention policy
  • PCAP file retention default 7d
  • JA3/JA4 fingerprint summary retention indefinite

Key telemetry

  • span_packets_captured_total{tier} — capture throughput
  • span_tls_handshakes_extracted_total{ja3_hash} — TLS fingerprint hits
  • span_dut_correlation_drops_detected_total — Syslog drops caught
  • span_pcap_storage_bytes