Network packet capture & analysis

Investigate the outage after it’s over.

Capuris records traffic at your network’s capture points. Search retained packets, compare observation points, and share the evidence your team needs to resolve an incident—even after service recovers.

TAAFCCCE
Up to 100 GbpsCapture R1 · aggregate capture rate
Up to 200 GbpsCapture R2 · aggregate capture rate
Standard PCAPShare evidence with existing tools

Find where the delay begins.

Start with the incident window. Follow the same exchange at two observation points. Give the next team a finding they can check against the original packets.

A slow application request

From reported delay to a reviewable finding.

Illustrative workflow · sample data

Step 01 / 03

Start with the slow request.

A user reports a delay at 09:41 UTC. Search the retained captures from the application and database sides for the same endpoints and incident window.

What you take forwardOne flow. Two observation points.

For this example, both capture points have synchronized clocks, equivalent filters, and no reported capture drops.

How to search packet history
Incident window · UTC
09:41:00–09:42:00
Capture points
Application side + database side
Matching filterhost 192.0.2.10 and host 198.51.100.20 and tcp port 5432
Request transit2 ms
Database-side response gap800 ms
Return transit2 ms
Matching exchanges at both observation points
Time · UTCCapture pointObservationElapsed
09:41:12.004Application sideRequest observed+0 ms
09:41:12.006Database sideSame request observed+2 ms
09:41:12.806Database sideResponse observed+802 ms
09:41:12.808Application sideSame response observed+804 ms

Sample timestamps demonstrate the analysis method. This illustration is not a product screenshot, customer result, or performance benchmark.

01 / Record

Capuris Capture retains traffic at the observation point.

02 / Investigate

Capuris Control & Insight support packet search, comparison, and analysis.

03 / Share

Standard PCAP keeps the original exchanges available to your team’s tools.

A specific question.
Evidence you can act on.

Outages, slow transactions, disputed ownership: begin with the problem in front of you, then narrow the traffic to the exchanges that explain it.

01

Catch an intermittent outage.

Return to the incident window after service recovers. Compare the affected flow with a healthy interval to find the first change.

The evidenceA timeline of the first failing exchange
Investigate a retry storm
02

Separate network delay from application delay.

Follow the same transaction at two capture points. Compare transit time, retransmissions, and the wait for a response.

The evidencePacket timing that narrows the next investigation
Locate a transaction delay
03

Verify a network change.

Compare traffic before and after a firewall or routing change. Check which connections complete, reset, or disappear along the path.

The evidenceA pass/fail record with the supporting packets
Validate a change
04

Resolve a multi-vendor incident.

Align captures from different observation points and identify where the flow changes. Give each vendor the same evidence to review.

The evidenceMatching captures and one shared finding
Build a shared timeline

Choose capture that fits your network.

Match the appliance to measured peak traffic, required retention, and available interfaces. Use Capuris Control to configure recording and search, and Insight to analyze the retained traffic.

  • Retain traffic with capture filters and file rotation
  • Search by time, host, port, and protocol
  • Compare traffic from multiple observation points
  • Export standard PCAP for existing tools
  • Automate capture and search with the Control API
  • Replay traffic in approved test environments
Plan your deployment
Capuris network capture appliance
Capuris capture hardware. Compare the documented deployment profiles below when selecting a model.
ComplianceTAA · FCC · CE

Four deployment profiles.

Model details & sizing
Published maximum aggregate capture profiles
ModelFormatCapture profileTypical use
Capture P1PortableUp to 10 GbpsField work and targeted investigations
Capture R11U rackUp to 100 GbpsBranch, campus, and datacenter capture
Capture R22U rackUp to 200 GbpsHigh-volume capture and greater local retention
Capture VirtualVirtual applianceHost-dependentLabs, cloud networks, and virtual environments

Size for the traffic you will retain. Physical rates are model-level aggregate maxima, not per-port guarantees. Achievable recording performance depends on adapters, packet sizes, storage, filtering, compression, and host configuration. Virtual capture also depends on the mirror source, virtual networking, and host scheduling.

Validate recording under representative load and check capture-drop counters. Confirm current interfaces, usable storage, and retention with Capuris. Read the sizing guidance or review capture validation.

Built for the people who keep networks running.

Since 2016, Capuris has combined packet-capture hardware with search and analysis software. We help network and security teams reconstruct incidents, compare what different capture points recorded, and put reviewable evidence in the hands of the team investigating the cause.

2016Founded
PCAPOpen evidence format
24/7Continuous visibility

Plan for the next incident.

Keep the packets you’ll need to explain it.