Logging attack packets for analysis is an effective means of preparing for future attacks. A packet log is created by a Sensor capturing the network traffic around an offending transmission. An expert in protocol analysis can use the log information to determine what caused the alert and what can be done to prevent future alerts of the same nature. Packet logs are retrieved from the database via the Attack Log and can be opened and examined using a program called Wireshark. By default, UDP and TCP protocol attacks generate a packet log for the attack plus the previous 128 bytes in the flow. You can configure to enable previous 256 bytes logging using the Sensor CLI. For more information, see the CLI commands section.
Tip
Trellix recommends using Wireshark (formerly known as Ethereal) for packet log viewing. Wireshark is a network protocol analyzer for Unix and Windows servers that enables you to examine the data captured by your Sensor. For information on downloading and use of Wireshark, go to www.wireshark.org.