You can request a PCAP by clicking on the PCAP button that is present on bro_conn class events. This will place the retrieval request into the queue, which can be found on the main PCAPs page.
Enter a search query containing
class=bro_connin the Search field.Select a time interval (default: Past 7 Days).
Select a Comm Broker by using the CB drop-down menu (default: All).
Click the search icon to run the search.
After viewing your search results, you need to process the PCAP. After processing, the PCAP transcript is available in Helix Enterprise. Optionally, you can upload the raw PCAP file, as well.
Ensure that you are viewing search results in the list view. If you need to switch your view, select List View from the drop-down menu in the upper-right corner of the results window.
Click the PCAP link to the right of your search result to bring up the PCAP Retrieval Options window.
(Optional) Select the Upload raw PCAP option. This uploads the actual raw PCAP file (as well as the transcript) to the Helix Enterprise Virtual Private Cloud (VPC) and makes it available for download from within Helix Enterprise. Note that you would only need this option if you do not have access to the raw files at your site.
Click Process PCAP to process the PCAP and upload the transcript to Helix Enterprise.