Deployment architecture overview

DNCA consists of software that is running on a host, which directly connects to the collection device, a network tap, or switch spanning port. The data flow from the collection device to the host workstation is unidirectional; the host only receives data passively.

From the host, the DNCA software transports the data in real time to the Discover Server environment. Data can be transported over TCP/IP or through a network crossover cable that is connected directly between the Network Capture Application host and the receiver workstation in the Discover environment. DNCA performs the following functions:

  • Reconstruct the HTTP(S) request and response bodies from the captured TCP/IP packet data
  • Decrypt SSL (if applicable)
  • (optional) Sessionize (or sequence) the HTTP request and response pages by a session ID into visitor sessions
  • (optional) Privacy blocking can be defined for sensitive data
  • Transport the data to the Discover Server environment