Capabilities
The LARK monitors network traffic passively. A copy of traffic is delivered to the appliance from a TAP or a switch SPAN (mirror) port, allowing the appliance to observe all traffic crossing the monitored link without sitting inline and without risk to production traffic. From that traffic, the appliance generates structured telemetry, detects suspicious activity, retains full packet data for forensic review, and presents the results through a set of web-based tools. An onboard AI layer supports summarization, natural-language investigation, and workflow automation across the collected data, running entirely on the appliance.Network visibility
Continuous monitoring of east-west and north-south traffic, with full packet capture and protocol-level logging.
Threat detection
Signature-based intrusion detection and file analysis applied to network traffic as it is observed.
Investigation
Analyst tools for querying, correlating, and visualizing collected data to investigate anomalies.
AI-assisted analysis
Local large language model inference for summarization, investigative assistance, and automation.
Architecture
The LARK runs its entire software stack as containerized services managed by a Kubernetes-based orchestration layer. Every capability, from the network sensors through storage, analytics, and AI, runs locally on the appliance. No external compute or cloud connectivity is required for normal operation, so the appliance can operate in isolated or air-gapped environments provided a traffic source is available at the capture interface. The containerized design isolates components from one another, allows individual services to be added, updated, or removed without disturbing the rest of the system, and enforces resource boundaries so that no single workload can starve the others.The LARK product line
The LARK is available in three models. All three run the same software and operate identically. They differ in compute, memory, and storage capacity, and the largest model runs across multiple nodes rather than one.Because all three models behave identically in operation, this documentation applies to every model unless a page indicates otherwise. Capacity and hardware differences between models are detailed on the models and capacity page.