Sniffer Recording & Forensic History
The sniffer never stops recording — so the evidence is still there three weeks later.
Most monitoring only knows about now. When the question is about last Tuesday at 14:20, it has nothing — the moment passed and the evidence went with it. The Net-Monitor sniffer records continuously and keeps what it records, so you can go back to any point in time and see exactly what was on the wire. Continuous 24/7 recording and long-term retention come with NM-Security Cyber; NM-Network Monitoring includes the same sniffer for shorter, on-demand capture sessions while you are chasing a problem.
What this means for you
- Answer "what happened last Tuesday?" with evidence
- Investigate an incident nobody was watching live
- Support audit, compliance and insurance questions
- Settle a supplier dispute with a record, not an opinion
What it actually does.
Sniffer recording, 24/7
With NM-Security Cyber the sniffer records around the clock rather than on demand, so there is no window in which something happens unrecorded because nobody had started a capture yet.
Data saved for future research
Sniffer data is retained rather than discarded after analysis, so the evidence outlives the incident that produced it.
Search back through history
Query stored history by host, interface, protocol or conversation to find exactly when a behaviour started — and what it looked like before it did.
Reconstruct the moment
Return to a specific minute and examine the traffic as it actually was, instead of reasoning backwards from a graph and a memory.
Evidence for audit and dispute
A factual record of what the network was doing, for auditors, insurers, regulators, or a supplier who says the problem was not theirs.
Feeds your existing stack
Interfaces to external systems over a standard open API, so stored evidence is available to the SIEM or case-management tools you already run.
How it looks day to day.
The same correlated data behind every view, so you are never comparing two tools that disagree.
Discovered devices
| DEVICE | TYPE | PORTS | LOAD |
|---|---|---|---|
| core-1 | Router | 48/48 | 62% |
| core-2 | Router | 48/48 | 55% |
| dist-3 | Switch | 96/96 | 71% |
| acc-3 | Switch | 46/48 | 94% |
| acc-4 | Switch | 48/48 | 38% |
Physical map
WAN-1 utilisation
38%
WAN-2 utilisation
41%
Response time
480ms
Conversations on this link
LINK ONLY 38% USED
- Backup replication10.4.18.2234%
- File share (SMB)10.4.2.5124%
- Video conferencing10.4.9.14017%
- Database sync10.4.31.812%
- Everything else—13%
- Retransmit storm on Gi0/3acc-3
Sniffer recording packets · +412% vs baseline · duplex mismatch suspected
9614:36 - Unusual east-west conversation10.4.18.22
NetFlow · new peer pair, 3.1 GB in 20 min, off-hours
7114:22 - Latency drift on WAN-2core-2
SNMP + sniffer recording packets · RTT trending up 6 hours
6411:08 - Baseline re-learneddist-3
Model updated after sustained topology change
1209:41
Recent configuration changes
142 DEVICES BACKED UP · 2 DRIFTED
- OFF BASELINE
interface Gi0/3 speed 100 → auto
acc-3 · n.levi · 14:31
ACL 120 — 2 lines added
core-1 · automation · 11:55
VLAN 340 created
dist-2 · m.cohen · Yesterday
- OFF BASELINE
SNMP community updated
acc-5 · n.levi · Yesterday
Illustrative views representing Net-Monitor output.
It does not stop here.
See it against your own network.
Book a short session with one of our engineers. We will run Net-Monitor against your own network and show you exactly what it finds — no slideware, no obligation.