Packet captures are an important part of the network engineers toolkit. They provide a look into what is really going on in your network and help get to the bottom of troubleshooting an issue very quickly. In addition to getting to the bottom of a problem, they also serve as a great learning tool to get a better understanding of how different protocols work, and more importantly how they work in your network. A company called QA cafe has a really great product called Cloudshark, that allows you to manage and analyze your packet captures without installing any software like Wireshark locally. Everything is handled in the web browser. I wanted to write a quick post to take a look at the available options from Cloudshark and how they might work best for you.
Cloudshark was intended to be used as a hardware or VM appliance within a company. Employees could then upload packet captures to the appliance for storage and analysis. They currently offer a Solo, Professional, and Enterprise version, with the biggest difference being the number of accounts you can create on each and an ability to integrate with Active Directory for the enterprise version. I recently setup the enterprise VM appliance and it was extremely quick to get going, requiring barely any input from me. If you aren’t sure if you want to commit to spending money on the product and want to try it out, or need to send someone a packet capture (that doesn’t contain sensitive information) for further review, they do have a page that allows you to upload up to 10MB of a capture, and then will generate a URL you can send off to someone else. I encourage you to check it out here:https://appliance.cloudshark.org/upload/
Cloudshark really worked to get as many features from Wireshark into the web based product, to the point that sometimes you forget that you are working in a web browser. When you first login to the product you are presented with a page that has a list of your currently uploaded files, as well as a place to upload new files, or search for a saved capture. The interface is clean, and easy to find what you’re looking for.