MÓDULO SPAN.Art¶
Line-rate packet capture — libpcap → AF_XDP → DPDK → SmartNIC tiers.
Function¶
Captures bench-side packets at line rate, extracts TLS metadata (JA3/JA4/cipher/SNI/ALPN), cross-correlates with NGFW Syslog records to detect log drops + misclassification. Feeds richest URL source into PURE Discovery Hub (source #6).
See primer for operator-facing intro.
Identity¶
| Element | Value |
|---|---|
| Plane | DATA (data-plane capture) — MGMT entry via OOBI |
| Internal code | span-collector |
| K8s namespace | span-art |
| OOBI slot | .230 |
| Capture iface | per-bench (sniff target, e.g. mirror port) |
5 ingest tiers (pick at install)¶
| Tier | Backend | Bandwidth |
|---|---|---|
| T1 | libpcap | up to 1 Gbps |
| T2 | AF_XDP | 1-10 Gbps |
| T3 | DPDK | 10-40 Gbps |
| T4 | SmartNIC offload | 40-100 Gbps |
| T5 | external switch SPAN | 100+ Gbps |
Operator controls¶
/admin/span— ingest tier selector, retention policy- PCAP file retention default 7d
- JA3/JA4 fingerprint summary retention indefinite
Key telemetry¶
span_packets_captured_total{tier}— capture throughputspan_tls_handshakes_extracted_total{ja3_hash}— TLS fingerprint hitsspan_dut_correlation_drops_detected_total— Syslog drops caughtspan_pcap_storage_bytes
Related¶
- ADR 0024
- SPAN.Art primer
- PURE primer — Discovery Source #6
- Patent claim #16