Overview
Provides instructions for downloading forensic capture files of DoS attacks from the Threat 360° view inCatalyst Center. Details the requirements for verifying network connectivity and enabling forensic capture on AP profiles to successfully retrieve and analyze pcap files for security investigations.
This procedure explains how to download the forensic capture of various DoS attacks from the Threat 360° view.
Catalyst Center enables or disables forensic capture only on the default AP profile. You must enable or disable forensic capture in existing deployments where you have created custom AP join profiles.
Before you begin
Verify the network connectivity between the APs and Catalyst Center.
Procedure
| 1. | From the main menu, choose . |
|
| 2. | In the Threat MAC address column, click the aWIPS attack link. The Threat 360 window opens. |
|
| 3. | Click the Forensic Capture tab to view information such as Detecting AP, Alarm ID, CaptureFilename, and Last Updated. |
|
| 4. | In the Capture Filename column, click the pcap file to download the aWIPS profile forensic capture. |
|
| 5. | Click Download All to download all the pcap files. |
|
| 6. | Click the Filter icon to narrow down the search results based on Detecting AP. |
|
| 7. | Click the Export icon to save the CSV file to your workspace.
|