The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Download alert PCAP Files as ZIP request

Prev Next

Downloads available PCAP files of the alert specified by alert ID, in a zip file.

GET https://<etp_instance_addr>/api/v2/public/alerts/<alert_id>/packet-capture

Use the alert ID from the alert search response (this is a part of the API endpoint URL).

Required header

x-fireeye-api-key: <key>—Specifies your personal API key. (For FireEye IAM users)

Authorization: Bearer xxxx - Specifies your API access token (For Trellix IAM users)

Example of an alert request

GET https://<etp_instance_addr>/api/v2/public/alerts/3yINFWA-1111152-8784f526-be90-45ed-8867-ec1fcf066dd8/packet-capture

Download alert PCAP files as ZIP response

The downloaded zip is password protected, and the password is "infected".

Zip File (Binary)
<num>-pcap.zip

cURL code sample: download alert PCAP files as ZIP

curl -X GET --location '<etp_instance_addr>/api/v2/public/alerts/3z2CMr6-20265-654e95de-7d13-46f2-9de9-ab2b0e8a45f4-eb2247de/packet-capture' -o file.zip --header 'x-fireeye-api-key: xxxxx'

This cURL sample includes the following options:

  • --header 'x-fireeye-api-key: xxxxxxxxxxxxxxx'—This header specifies your personal API key. Use the access token if you are a Trellix IAM user.

  • https://<etp_instance_addr>/api/v2/public/alerts/3z2CMr6-20265-654e95de-7d13-46f2-9de9-ab2b0e8a45f4-eb2247de/packet-capture - The request URL

Results

This example downloads all PCAP files of the specified alert in a zip file.