← Go back to library

Download PCAP from Endace Probe triggered by intrusion detection

Receive intrusion alerts from Elastic when unusual activity is detected. Collect information from an Endace Probe on the affected firewall and format a PCAP file containing the network traffic for the time period. Send the information to a user via email allowing them to investigate efficiently.

Community author

Roberto Cordeiro at Endace

How it works

Import this story to your tenant, from where you can adapt it to meet your unique needs.

Import
Was this story helpful?