Skip to content
OBSERVE. ANALYZE. ACT.
Support Login

Packets / Capture and evidence

Keep the evidence behind every investigation.

Preserve live traffic, bring in field captures, and return to the evidence when an issue needs a closer look. 01Layer connects capture storage, targeted inspection, metadata analysis, and trace export in a shared workflow.

Live traffic and uploaded capture files support retained evidence, targeted inspection, metadata analysis, export, and replay workflows.
View the workflow at full size

Retain what matters

Choose the traffic, storage destination, and capture policy.

Investigate with context

Narrow evidence by time, address, protocol, and content.

Reuse the trace

Export selected traffic or carry it into analysis and replay.

Capture choices

Select the evidence path for the job.

FlowMagic Capture Services provides managed capture, direct PCAP writing, and metadata extraction as distinct NextIO components.

Managed capture

Retain a continuing history

Packet Capture writes to the managed storage subsystem through a selected data container. Configure capture format, file limits, start conditions, and runtime resources.

Packet Capture controls

PCAP writing

Create a focused trace

Packet Writer writes received traffic to a PCAP location with a file prefix and size limit. Optional timestamp reordering uses a configured window and queue capacity.

Packet Writer controls

Post-capture context

Make the evidence searchable

Metadata extracts and reports information from captured traffic. Select address, protocol, port, VLAN, and DNS indexes that support the investigation.

Metadata capability

Managed retention

Define what you keep and how it rotates.

Capture Service supports local disks, NVMe, RAID, NAS over NFS, iSCSI block storage, and RAM-backed targets. Data containers organize the selected storage with quota and rotation behavior.

Data container
Prepare and enable the selected storage, create the container, and assign it to the capture component.
Capture content
Choose the capture file format. Optional truncation by byte offset or protocol layer changes how much of each frame is retained.
File boundaries
Set preferred maximum file size, maximum packets per file, and maximum duration per capture file.
Capture runtime
Set start conditions, worker and file-writer counts, buffer size, and compute allocation for the service.

Truncation removes evidence beyond the selected boundary. Size retention and capture content around the investigation and replay requirements.

Packet Capture format and storage properties
Capture format, file limits, and data-container selection in NextIO. View full size.

Focused inspection

Move from the time window to the evidence.

Use the timeline to isolate an event, inspect the selected traffic, and export a trace that another team can reproduce.

Packet viewer with timeline, traffic rows, and decoded DNS details
The existing packet viewer combines a time navigator, traffic timeline, packet rows, and decoded fields. View full size.

Narrow the investigation

Target a time window, IP address, IP list or range, BPF expression, or regular expression in the supported capture and analysis workflows. Review the protocol fields and chronology needed to explain the event.

Share a reproducible trace

Export the selected evidence as PCAP for external analysis or lab reproduction. Keep the selected source and time window with the findings so another operator can follow the same investigation.

Live evidence and field captures

Bring current and historical traffic together.

The Joint Realtime and PCAP Analysis workflow accepts remote PCAP and PCAPng uploads, monitored folders, multi-file batches, and continuing live capture.

Evidence intake choices
SourceWorkflowInvestigation value
Live captureCollect selected site traffic continuously.Review current conditions while retaining evidence for later questions.
PCAP / PCAPng uploadUpload a remote or manually collected trace.Bring a field observation into the same analysis environment.
Monitored folderProcess files arriving in a watched collection location.Use a repeatable intake path for ongoing evidence submissions.
Multiple capture filesSelect timestamp merge when chronology across sources matters.Review a time-ordered traffic set for investigation, profiling, or replay.

From capture to action

Keep the investigation connected.

Plan storage and analysis together so the needed evidence is still available when an incident is reviewed.

  1. Select and prepare the source

    Connect live traffic through the required filtering or processing path, or choose an uploaded capture set.

  2. Set capture and retention

    Choose the data container, quota, format, file boundaries, and any truncation. Align metadata and raw capture retention windows.

  3. Focus the analysis

    Select the event window and targeting criteria. Inspect protocol context, timelines, and the relevant traffic rows.

  4. Carry the finding forward

    Export a scoped trace, document the analysis in a notebook, or use replay to reproduce the condition in a validation environment.

Keep exploring

From overview to operation.

Open the function descriptions, component controls, and related workflows behind this capability.

Preserve the evidence your team needs.

Discuss the sources, service requirements, and deployment that fit your operation.

Talk to our team