Downloads available PCAP files of the alert specified by alert ID, in a zip file.
GET https://<etp_instance_addr>/api/v2/public/alerts/<alert_id>/packet-capture
Use the alert ID from the alert search response (this is a part of the API endpoint URL).
Required header
x-fireeye-api-key: <key>—Specifies your personal API key. (For FireEye IAM users)
Authorization: Bearer xxxx - Specifies your API access token (For Trellix IAM users)
Example of an alert request
GET https://<etp_instance_addr>/api/v2/public/alerts/3yINFWA-1111152-8784f526-be90-45ed-8867-ec1fcf066dd8/packet-capture
Download alert PCAP files as ZIP response
The downloaded zip is password protected, and the password is "infected".
Zip File (Binary) <num>-pcap.zip
cURL code sample: download alert PCAP files as ZIP
curl -X GET --location '<etp_instance_addr>/api/v2/public/alerts/3z2CMr6-20265-654e95de-7d13-46f2-9de9-ab2b0e8a45f4-eb2247de/packet-capture' -o file.zip --header 'x-fireeye-api-key: xxxxx'
This cURL sample includes the following options:
--header 'x-fireeye-api-key: xxxxxxxxxxxxxxx'—This header specifies your personal API key. Use the access token if you are a Trellix IAM user.https://<etp_instance_addr>/api/v2/public/alerts/3z2CMr6-20265-654e95de-7d13-46f2-9de9-ab2b0e8a45f4-eb2247de/packet-capture- The request URL
Results
This example downloads all PCAP files of the specified alert in a zip file.