NDR can pull packets for any recorded flow on any connected PX and return the packets in industry-standard PCAP format.
Note
This feature works only when the packets are still contained on the PX. Packets are purged when the storage available on the connected PX appliances is 80% full. When this condition happens, pivoting to the packets will not succeed since the packets are no longer stored.
The events shown in the event table are from the search results. If the events are not part of the search results, the packets cannot be retrieved from the user interface.
After the events of interest are selected, you have two choices: download the packets directly from the PX in PCAP format or store them in PCAP format with a case. If you download the PCAP file directly, you can view it in any tool that can import nanosecond timestamped PCAP format. For example, you can view the PCAP in WireShark. If you store the file, you must assign it to a case and also name the file for later review. After it is stored to a case, you can download it later and it is not purged.
Note
The current limit for stored PCAP files is 2 TB.
Click
and from INVESTIGATION, select Search.Perform a search.
Select the check box in the event table for the PCAP you want to download.
Select Download PCAP to download or store the selected PCAP.