Skip to content
Discussion options

You must be logged in to vote

Go to Alerts or Hunt and find a log for an EXE. Click on the alert to access the Quick Actions Menu. Then click the PCAP action.

For more information, please see:
https://docs.securityonion.net/en/2.3/alerts.html#actions
https://docs.securityonion.net/en/2.3/hunt.html#actions
https://docs.securityonion.net/en/2.3/pcap.html

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by defensivedepth
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants