The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Send the captured file to the Manager

Prev Next

To start the capture and send the captured file to the Manager:

Task

  1. For a standalone Sensor, select Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Packet Capturing → Capture Now.
    For Sensors in a stack, select Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → <Stackname-node id> → Troubleshooting → Packet Capturing → Capture Now.
  2. From the Send Captured Packets To drop-down list, select The Manager.
  3. Type the maximum file size to be captured in the Maximum Capture Size (MB) field.

    Note

    The maximum file size can be configured up to the maximum value of Sensor defined limits.

  4. Configure the Capture Rules.

    Note

    If you are configuring for a Sensor from a stack of NS9500 Sensors, you cannot configure rules at an interface level. You have to configure to All interface.

  5. Click Save to save the capture settings.
  6. Click Start.
    When the maximum file size is reached, the Sensor uploads the captured file to the Manager.
  7. To stop the packet capture session, before the configured maximum file size, click Stop. The Sensor pushes the captured file to the Manager.
  8. Click Cancel. The Sensor stops the capture and deletes the captured file.

    Note

    If file upload has started then it cannot be canceled.