Windows Agent Flow Captures: For All Windows OS Excluding Windows Server 2008 R2
From the latest version of Windows, the agent uses ndiscap.sys (Microsoft in-built) driver and Events Tracing using Windows (ETW) framework to capture the network flows.
During the upgrade to the latest version:
-
The agent switches to ndiscap.sys from npcap.sys.
-
The agent installer uninstalls Npcap if:
-
Npcap is installed by the agent.
-
Npcap is not in use.
-
OS version is not Windows Server 2008 R2.
-
After the agent services are started, the agent creates ETW sessions, CSW_MonNet, and CSW_MonDns (for DNS data), and initiates the capture of network flows.
|
|