To start the capture and send the captured file to the Manager:
Task
-
For a standalone Sensor, select
Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Packet Capturing → Capture Now.
For Sensors in a stack, select Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → <Stackname-node id> → Troubleshooting → Packet Capturing → Capture Now.
- From the Send Captured Packets To drop-down list, select The Manager.
-
Type the maximum file size to be captured in the
Maximum Capture Size (MB) field.
Note
The maximum file size can be configured up to the maximum value of Sensor defined limits.
-
Configure the
Capture Rules.
Note
If you are configuring for a Sensor from a stack of NS9500 Sensors, you cannot configure rules at an interface level. You have to configure to All interface.
- Click Save to save the capture settings.
-
Click
Start.
When the maximum file size is reached, the Sensor uploads the captured file to the Manager.
- To stop the packet capture session, before the configured maximum file size, click Stop. The Sensor pushes the captured file to the Manager.
-
Click
Cancel. The Sensor stops the capture and deletes the captured file.
Note
If file upload has started then it cannot be canceled.