If you’re reading this blog then there’s a good chance that you already recognise the importance of highly accurate packet capture within your monitoring and security infrastructure(s) which is music to our ears. But as most professionals know, actually achieving zero packet loss is far from straightforward.
The bit that most people miss is that it doesn’t matter how good your software application is, if it’s missing packets then the results will be nonsense. To achieve 100% packet analysis – which is actually a more precise definition that 100% packet capture – you need to take a step back and look at the whole end to end journey that a packet takes between the wire and the application. If you are passively monitoring stageful traffic, one packet lost can void analysis for the entire session, and if that session is days long, then you loose the lot, or if you are going to stand up in court to validate some analysis, then you need to know you have it all.