To configure the correct operation of the Traffic Parsing section, you must add equipment of the "Pcap Parsing Server" type to the Equipment List Management section.
Traffic parsing equipment configuration:
To install the necessary utilities, run the following command:
apt install wireshark tshark sox
To go to the traffic parsing section in the menu, go to the "Lawful interception"→"Traffic parsing"→"Traffic parsing" section.
The Traffic Parsing section looks like the figure below.
The tasks for Traffic Mining are located on the left side of the Traffic Mining page.
To create a new Traffic Analysis task, click the "+" button in the toolbar above the list of existing tasks.
In the task creation form that opens, enter:
Click the "Save" button.
To edit a task, click the edit button next to an existing task.
In the task editing form that opens, change:
Click the "Save" button.
To delete a task, click the "Delete" button next to the existing task and confirm or cancel the action.
The files for Traffic Parsing are located in the central part of the Traffic Parsing page.
To add a new file for Traffic Parsing, click on the "+" button in the toolbar above the list of added files.
In the opened form for adding a file:
Click the "Save" button.
To edit a file for Traffic Parsing, click the edit button next to an existing file.
In the file editing form that opens, you can change:
Click the "Save" button.
If changes have been made to the types of traffic parsing, a confirmation form for restarting traffic parsing for this file will appear on the screen.
To delete a file, click on the "Delete" button next to the existing file and confirm or cancel the action.
To restart file parsing:
Files for traffic parsing can be imported from the "Traffic Capture" section.
Go to the "Lawful Interception"→"Traffic Capture" section.
In the list of files, select the files you want to parse and click the parse button.
In the opened form:
Click on the "Apply" button. After the file import process is completed, a window will appear prompting you to go to the "Traffic Analysis" section.
The Web parsing results tab displays HTTP requests.
The "Requests" tab displays "raw" data about requests.
The following data is available in the table:
When you click on the "Additional information about the request" (?) button, a popup will open with additional information about the request:
The DNS parsing results tab displays the hosts.
The following data is available in the table:
When you click on the "Additional information about the request" (?) button, a popup will open with additional information about the request:
On the MAIL parsing results tab, sent/received Emails.
The following data is available in the table:
When you click on the Message Content button, a popup will open in which are available:
Clicking on the Additional Information(?) button will open a popup with additional information about the letter:
On the Voip parsing results tab, information about completed Voip sessions.
The following data is available in the table:
When you click on the Recordings button, a popup will open where you can listen to audio recordings:
When you click on the "Additional information" (?) button, a popup will open with additional information about the session:
The FTP parsing results tab displays files sent/received via FTP. The following data is available in the table:
When you click on the "Additional information" (?) button, a popup will open with additional information about the request: