Atlas Knowledge Base
Dashboard
SBN Splitter

SBN Splitter


SBN Splitter

The SBN Splitter can used during conversions from a third party automation system to SBN to capture signals from an alarm receiver. This splitter will simultaneously parse TCP/IP traffic from the receiver to the third party automation and to an SBN Concentrator.

The splitter supports two operating modes:

  1. Active mode -- the original behavior described in the sections below. The splitter terminates the live TCP connection between the receiver and the existing automation, and forwards bytes to the SBN Concentrator and any other configured destinations.
  2. SPAN mode -- introduced in v95 (PR #1040). The splitter sits passively on an internal-network SPAN/mirror port and reassembles traffic between the alarm receivers and the existing automation without sitting in the live TCP path. See SPAN Mode (Passive Tap).

Once installed, the SBN Splitter becomes part of the critical alarm signal path and should be treated as a production element. The SBN Splitter process and error log should therefore be monitored in the same way as other receiver infrastructure. The SBN Concentrator will send alerts on an SBN error account if it detects that the Splitter is no longer operational.

Overview

Before go live

The SBN Splitter is placed as a server / client between the Receiver and the existing automation.

Every data packet transmitted from the receiver is

  1. Forwarded to the automation
  2. Forwarded to the SBN Concentrator

Every data packet transmitted from the automation is:

  1. Forwarded only to the receiver

Every data packet transmitted from the SBN Concetrator is ignored.

In this way, the SBN Concentrator can receive the receiver signals without interfering with the processing of the existing Automation.

Overview of the SBN Splitter before go live

After go live

The SBN Splitter is placed as a server / client between the Receiver and the SBN Concentrator.

Every data packet transmitted from the receiver is

  1. Forwarded to the SBN Concentrator
  2. Forwarded to the previous automation

Every data packet transmitted from the SBN Concentrator is:

  1. Forwarded only to the receiver

Every data packet transmitted from the existing automation is ignored.

In this way, the previous automation can receive the receiver signals allowing for a record to be maintained in the existing automation.

Overview of the SBN Splitter after go live

Installation

The SBN Splitter can be downloaded from the Innovative FTP website [ftps://ftp.innovative247.com/common/Releases/SBN_Conc/94]. The splitter is compatible with Windows, Linux, and MacOS. The relevant version should be copied to a local directory. A sample configuration has been included.

SPAN Mode (Passive Tap)

SPAN mode is an alternative front end for the same sbn-splitter binary. Instead of the splitter terminating the receiver-to-automation TCP connection, the splitter sits on a switch SPAN/mirror port (or an inline network tap), passively reassembles the receiver-to-automation traffic from mirrored packets, and forwards the reassembled byte stream downstream to the SBN Concentrator and any other configured destinations.

The destinations side of the configuration -- the destinations: list under each splitter, and the Concentrator wiring -- is unchanged between active and SPAN mode. Only the front end differs. Removing the span: block from the configuration falls back to active mode.

When to use SPAN mode

Use SPAN mode in environments where:

  1. The existing automation cannot be reconfigured to point at a new IP/port.

Prerequisites

  1. Capture tool on PATH -- the daemon checks at startup and refuses to start with a clear install hint if missing:
  2. Linux/macOS: tcpdump
  3. Windows: dumpcap (ships with Wireshark, https://www.wireshark.org/download.html)
  4. Privileges for live capture:
  5. Linux: run the splitter as root, OR grant tcpdump the right capabilities (sudo setcap cap_net_raw,cap_net_admin+eip /usr/bin/tcpdump), OR run the splitter under sudo.
  6. Windows: launch the splitter daemon as Administrator (or configure Npcap for non-admin capture).
  7. The pcapFile: replay form (see below) needs no special privileges.
  8. NIC. The switch SPAN port should mirror the receiver-to-automation traffic on the internal network to a dedicated NIC on the splitter host; configure that NIC name in the interface: field.

Replay (pcapFile)

Setting span.pcapFile to a previously-captured .pcap file replays it through the same reassembly pipeline. This requires no NIC and no special privileges.

When pcapFile is set, interface: and bpf: are ignored.

Limitations

  1. TLS-encrypted traffic. SPAN capture is ciphertext-only on the wire; if the receiver-to-automation TCP connection is TLS-encrypted, the splitter cannot reassemble it in clear and cannot forward usable bytes to the SBN Concentrator. Sites using TLS must remain on active mode (or terminate TLS upstream of the splitter) while SPAN mode is in use.

Command line options

The SBN Splitter is a command line application that is run through a command shell such as PowerShell, CMD.EXE, or Bash.


Sample Command

Description

sbn-splitter start -c sample-config.yaml

Run the splitter with the configuration file sample-config.yaml

sbn-splitter start -ld

Run the splitter, enable verbose logging, and output log files to the standard output

sbn-splitter test echo 8000

Start a test echo server on port 8000

sbn-splitter test server 8001

Start a test server on port 8001

sbn-splitter test client 8002

Start a test client on port 8002

sbn-splitter daemon install -c sample-config.yaml

Install the sbn-splitter as a service

sbn-splitter daemon start -c sample-config.yaml

Start the sbn-splitter service

sbn-splitter daemon stop -c sample-config.yaml

Stop the sbn-splitter service

sbn-splitter daemon remove -c sample-config.yaml

Remove the sbn-splitter as a service

Configuration

The SBN Splitter is configured via configuration files. The sample configuration file provides an example of the receiver acting as a TCP Client and as a TCP Server.

It is best practice to create a splitter configuration per receiver rather than include multiple splitter configurations in one file. In this way, if a connection fails it will only affect one receiver.

A sample configuration file is provided below.

The splitter will validate the configuration and fail to start if it detects errors.

TCP Splitter options

General splitter options


Option

Description

Default Value

name

Name of the splitter


disabled

Whether the splitter is disabled

false

server

Definition of the server connection

N/A

client

Definition of the client connection

N/A

clientKeepAlive

Whether to keep the client connection alive when server disconnects

false

destinations

A list of additional connections

N/A

Server connection

Options related to the server connection


Option

Description

Default Value

name

Name of the connection

<none>

address

Network address to create the server listener

All network interfaces

port

Port number


log

Whether to log traffic coming from and to the server

false

rejectMultiple

Whether to reject multiple server connections

false

Destination connection

Options related to the client connection


Option

Description

Default Value

name

Name of the connection

<none>

address

Network address to connect to when a server connection is created

localhost

port

Port number

<none>

log

Whether to log traffic coming from and to the client

false

Destination

Options related to additional destinations


Option

Description

Default Value

name

Name of the connection

<none>

disabled

Whether the destination is disabled

false

address

Network address to connect to if acting as a client

localhost

port

Port number

<none>

listen

Whether to act as a server (listening) or as a client

false

log

Whether to log traffic coming from and to the connection

false

retry.interval

How often (in milliseconds) to retry establishing a connection when it fails. If zero, the connection will not be retried

<none>

retry.maxAttempts

How many attempts to try restablishing a connection when it fails. If zero, the connection will be retried continuously


tap.server

Whether to tap the server, sending messages from the server to the connection

false

tap.client

Whether to tap the client, sending messages from the client to the connection

false

SPAN options

SPAN mode is selected by the presence of an enabled span: block at the same level as splitters:. There is no separate mode field and no enabled flag. Each splitter's existing server.address, server.port, and client.address are reused as the SPAN flow coordinates -- the splitter builds an appropriate BPF filter automatically from those values.


Option

Description

Default

interface

NIC that receives the mirrored traffic from the switch SPAN port.

(required for live capture)

pcapFile

Path to a pre-captured .pcap file. When set, the splitter replays the file through reassembly instead of doing live capture; interface and bpf are ignored.


bpf

Override the auto-derived BPF filter.

auto-derived from each splitter's server/client definitions

snaplen

Per-packet capture length in bytes.

262144

bufferMb

Capture-tool kernel buffer size in MB (tcpdump -B / dumpcap -B).

64

flushIntervalMs

How often the assembler evicts idle flows.

250

flowIdleTimeoutSec

Silence threshold (seconds) before a flow is considered idle and evicted.

30

Sample configurations

Receiver client to Automation server

Receiver Client to Automation Server

# Configuration for sbn splitter with the receiver
# acting as a client
tcpsplitter:

# Provide a set of SBN Splitter configurations
# Note - Innovative recommends one configuration per file
-
# The name of the splitter
name: Receiver -> Automation
# Whether to keep the client connection open even if
# the server disconnects
clientKeeepAlive: false

# The client connection
client:
# Name
name: Automation

# Port
port: 8001

# Address - if not provided this will default to localhost
address: localhost

# Whether to log the traffic
log: false

# The server connection
server:
# Name
name: Receiver

# Port
port: 8000

# Address - if not provided this will default to localhost
address: localhost

# Whether to log the traffic
log: false

# Additional destinations to send IP traffic to. Note any responses
# from these destinations are discarded
destinations:
-
# Name
name: SBN Concentrator

# Whether the destination is disabled
disabled: false

# Port
port: 8002

# Retry
retry:
# Interval in milliseconds
interval: 5000

# Whether to log the traffic
log: false

# Which traffic should be tapped
tap:
server: true

Receiver server to Automation client

Receiver Server to Automation Client

# Configuration to sbn splitter with the receiver
# acting as a server
tcpsplitter:

-
# The name of the splitter
name: Automation -> Receiver

# Provide a set of SBN Splitter configurations
# Note - Innovative recommends one configuration per file
server:
# Name
name: Automation

# Port
port: 8001

# Whether to log the traffic
log: false

# The server connection
client:
# Name
name: Receiver

# Port
port: 8000

# Address - if not provided this will default to localhost
address: 127.0.0.1

# Whether to log the traffic
log: false

# Additional destinations to send IP traffic to. Note any responses
# from these destinations are discarded
destinations:
-
# Name
name: SBN Concentrator

# Whether the destination is disabled
disabled: false

listen: true

# Port
port: 8002

# Whether to log the traffic
log: false

# Which traffic should be tapped
tap:
client: true

SPAN mode passive tap

The canonical example ships with the splitter binary at exec/sbn-splitter/receiver-span-migration.yaml. A reduced version:

# sbn-splitter SPAN mode example.
#
# tcpdump (Linux/macOS) or dumpcap (Windows; ships with Wireshark) must be
# on PATH -- the daemon will refuse to start with a clear install hint if
# missing.

tcpsplitter:

# Splitter definitions. In SPAN mode, server.address / client.address
# encode the captured flow's endpoints on the internal network (which
# side is the alarm receiver vs. the automation determines direction).
# destinations: is unchanged from active mode.
splitters:
-
name: Automation -> Surgard III

server:
name: Surgard III
address: 10.0.0.10 # alarm-receiver IP (server side of the TCP flow)
port: 8000

client:
name: Automation
address: 10.0.0.5 # automation IP (client side of the flow)

destinations:
-
name: SBN Concentrator
port: 8002
retry:
interval: 5000
maxAttempts: 3
tap:
server: true

# SPAN front-end configuration. The BPF filter and the per-flow direction
# mapping are derived from each splitter's server.address / client.address /
# server.port above.
span:
# NIC that receives the mirrored traffic from the switch SPAN port.
interface: eth1

# Replay a pre-captured pcap file instead of live capture.
# When set, interface and bpf are ignored.
# pcapFile: /var/lib/sbn-splitter/captures/migration-2026-01.pcap

# Optional packet-capture tuning -- defaults shown.
# snaplen: 262144
# bufferMb: 64
# flushIntervalMs: 250
# flowIdleTimeoutSec: 30




Was this helpful?