The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manage captured files

Prev Next

To manage the captured files in the Manager:

  1. For a standalone Sensor, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Packet Capturing → PCAP Files.

    For Sensors in a stack, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → <Stackname-node id> → Troubleshooting → Packet Capturing → PCAP Files.

    For member Sensors in a cluster, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → <MemberSensorname-node id> → Troubleshooting → Packet Capturing → PCAP Files.

    The list of the captured files is stored in the Manager in a specific filename format.

  2. Select a specific file and click Open/Export.

    You can view the file or save it at the wanted location.

  3. To delete the selected file, click GUID-9A719AD5-F6BE-4CD4-9311-CC6655DF9B70-low.png.