-
Hi all! |
Beta Was this translation helpful? Give feedback.
Answered by
dougburks
Jul 29, 2021
Replies: 1 comment
-
Go to Alerts or Hunt and find a log for an EXE. Click on the alert to access the Quick Actions Menu. Then click the PCAP action. For more information, please see: |
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
defensivedepth
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Go to Alerts or Hunt and find a log for an EXE. Click on the alert to access the Quick Actions Menu. Then click the PCAP action.
For more information, please see:
https://docs.securityonion.net/en/2.3/alerts.html#actions
https://docs.securityonion.net/en/2.3/hunt.html#actions
https://docs.securityonion.net/en/2.3/pcap.html