Creating a Packet Capture
To create a new task, the selected account should have one or more sensors with the PCAP feature enabled.
To create a Packet Capture task:
- Go to Investigations > Packet Capture.
- Click Create Task. The Create New Packet Capture Task window opens.
- Configure the task settings.
Field Required Description Title Yes The name of the task. BPF Yes The BPF for traffic to match. Date Range Yes The interval that the task will be active for, default = the next 24 hours. Sensors No The sensors that the task will run on, default = All Sensors. Description No A description of the task. Sensors can only spool four (4) tasks at once, so only specify sensors that the task is relevant to. For example, if you are trying to troubleshoot one particular host in a particular data center, you probably only need to deploy the task to one sensor.
- Click Create.