Sensors Overview

The Sensors Overview page allows you to get an overview of all connected Passive and Active sensors.

After logging in the system for the first time, begin by adding Sensors, which are necessary to gain network visibility. The three type of available Sensors are: Passive Sensor, Active Sensor, and PCAP Replay Sensor.

Passive Sensors

The passive sensors table shows a list of enrolled passive sensors. For each passive Sensor, its name, address, IP reuse domain, the monitored network it applies to, as well as the health, monitoring and alert status of the Sensor is displayed.

There are two viewing options: Summary and Detailed. The views can be toggled using the dropdown menu above the table, in the top-right corner. The default view is Summary. When the Detailed view is selected, a more fine grained information about the status of the modules and profiles is shown, with various details such as the sensor name, encryption status, sensor address and more.

To quickly locate a specific passive Sensor it is possible to filter the list of Sensors by name, address, IP reuse domain and monitored network using the "fields" in the table's title bar.

Passive Sensors implement retention mechanisms to ensure maximum availability of critical data even in case of temporary disconnection from the Command Center. For more details, go to the data retention policy page.

Go to the Passive Sensors Settings page to learn more about the sensors and how to edit them.

Active Sensors

The active sensors table shows a list of enrolled active sensors, with various details such as the name, address, target network, IP reuse domain, the monitored network it applies to, the Sensor’s state and the number of pending tasks.

To quickly locate a specific active sensor, filter the list of Sensors by name, address, IP reuse domain and monitored network using the "fields" in the table's title bar.

For Active Sensors, all columns except the number of tasks can be used to quickly filter for a specific Sensor.

To delete one or more active sensors, select the checkbox in the first column, which enables the Delete icon above the active sensors table.

Go to the Active Sensors Settings page to learn more about the sensors and how to edit them.

PCAP Replay Sensors

In most cases, eyeInspect will be configured to monitor live traffic on the network. That way, any anomalous and potentially dangerous network events can be detected swiftly, and the assets inventory will be kept up-to-date.

For assessment purposes, eyeInspect may also be used to analyze recorded network traffic (PCAPs). For a user to be able to do this, they must have a Bundled Configuration with a valid Sensor license set up. When the PCAP Replay function is enabled, any user that has view/edit/remove permissions on Sensors may use this feature.

For assessments, PCAP Replay Sensors can be used for replaying data from PCAP files. For PCAP replay sensors, the sensor name will end with "(PCAP replay)".

Note: PCAP Replay Sensors are only available in bundled configurations.

The PCAP Replay Sensor settings are the same as the Passive Sensor, with the exception of one setting - PCAP. Go to the Passive Sensors Settings page to learn more.

To learn how to add a PCAP replay sensor, go to the Miscellaneous settings page.

Reload

Reloads the sensors.

New sensor

Allows you to add a new sensor. The following options are available - click an option to know more.

Pause

Pauses the sensors.

Configuration

Allows you to view the available configuration templates and identify which template is currently applied to each sensor. Navigate to Configuration > Templates overview.

IP reuse domains

Allows you to add IP reuse domains.

Monitored networks

Click Monitored networks to open the monitored networks dialog, containing a table of currently configured networks with name, address (CIDR notation), VLAN IDs, description and all associated sensors.

The following actions are possible in the Monitored networks dialog, by using the three icons above the table:

CSV Import

Import a list of monitored networks in CSV format.

CSV Export

Export the list of monitored networks in CSV format.

Add a new network

Use the add button (plus icon) to define a new monitored network. More details about the "Address" and "VLAN IDs" fields can be found by hovering over the question mark icon in the right corner of the field. Note that a sensor can be associated with a monitored network in the sensor's settings.

In addition, monitored networks for hosts which do not fall into any current network can be generated automatically by using the "Create missing networks" button and filling the form that shows up.

Editing an existing network

To edit the details of a monitored network, click anywhere on the row containing the network. After making the changes, click "Finish" to save your changes.

Removing an existing network(s)s

To remove one or more monitored networks, select them by checking the corresponding checkboxes and click the delete button (identified by the trash bin icon) on the top right corner of the table.