bottracker trace-save enable

Prev Next

Enables the bot tracker to save packets in a flow that matches Snort rules. Pcaps are saved in /data/bott/cs-traces.

This command is not supported onthe SmartVision Edition appliances, which are Network Security appliances with SmartVision edition appliance licenses. The SmartVision Edition sensor is also called Trellix Network Security, SmartVision Edition.

The bot tracker feature is enabled by default. It tracks callbacks and the entire infection life cycle. The bot tracker is available only when the SECURITY_CONTENT license is installed. This command is specific to the File Protect and Network Security appliances.

Syntax

[no] bottracker trace-save enable

Parameters

None

Example

The following example enables the bot tracker to save packets in a flow that matches Snort rules.

hostname (config) # bottracker trace-save enable

User role

Admin

Command mode

Config

Supported Appliances

  • Central Management System: Before release 6.4

  • File Protect: Before release 6.4

  • Network Security: Before release 6.4