Viewing a PCAP File for an Event
Enterasys IPS Reporting lets you download the session data for a given event in the form of a
PCAP file. This lets you view traffic data in an application such as Wireshark.
To view captured session traffic data for an event:
1.
In the Event Table pane, right click and select Download PCAP.
The File Download dialog box appears.
2.
Save the PCAP file locally.
3.
Unzip the PCAP file and open it in Wireshark or a similar application.
Enterasys IPS Analysis and Reporting Guide 8-1
8
Need help?
Do you have a question about the Intrusion Prevention System and is the answer not in the manual?