Skip to content

PCAP action does not exist in the actions menu #13987

Answered by dougburks
foxman0719 asked this question in 2.4
Discussion options

You must be logged in to vote

Looking at your first screenshot, it appears you are looking at the default Alerts view which is Grouped by Name, Module. If you select the Drilldown option on the context menu, then it should show you the individual alerts themselves. If you then click on an individual alert, you should see the PCAP option on the context menu.

From https://docs.securityonion.net/en/2.4/alerts.html#actions:

Clicking the PCAP option will pivot to the PCAP interface to retrieve full packet capture for the selected stream. This option will only appear if you click on a log that contains source IP, source port, destination IP, destination port, etc.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@foxman0719
Comment options

Answer selected by foxman0719
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants