PCAP action does not exist in the actions menu #13987
-
Version2.4.110 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU16 RAM64 Storage for /1T Storage for /nsm8T Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailI want to analyze packets in the PCAP option but they do not appear and I cannot send them from the actions menu because the option is not there. Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Looking at your first screenshot, it appears you are looking at the default Alerts view which is From https://docs.securityonion.net/en/2.4/alerts.html#actions:
|
Beta Was this translation helpful? Give feedback.
Looking at your first screenshot, it appears you are looking at the default Alerts view which is
Grouped by Name, Module
. If you select the Drilldown option on the context menu, then it should show you the individual alerts themselves. If you then click on an individual alert, you should see the PCAP option on the context menu.From https://docs.securityonion.net/en/2.4/alerts.html#actions: