Cisco Multicloud Defense User Guide

PDF

Cisco Multicloud Defense User Guide

Packet Capture Profile

Want to summarize with AI?

Log in

Learn how a Packet Capture Profile records cloud network packets for security investigations, incident reconstruction, and troubleshooting connectivity, latency, or packet loss.


Packet Capture (PCAP) captures data packets that are transmitted across the network, allowing for detailed analysis of the network traffic. PCAP can be used to monitor network traffic for signs of malicious activity by analyzing the captured packets, security systems can detect and respond to potential threats in real-time and allows you to reconstruct the sequence of events leading up to the incident and identify the source and nature of the attack. This information can be helpful in diagnosing a timeline or to troubleshoot events such as connectivity problems, latency, and packet loss.


Create a Packet Capture Profile

Use the following procedure to create a pack capture profile:

Procedure

1.

Navigate to Infrastructure > Profiles > Packet Capture.

2.

Click Create.

3.

Specify a unique Name.

4.

(Optional) Enter a Description. This may help differentiate between other profiles with a similar name.

5.

Specify a CSP Account.

6.

The type of cloud service provider may determine the parameters for the storage bucket. Be aware of the following requirments per cloud service provider:

  • AWS - S3 Bucket.

  • Azure - Storage Account Name, Blog Container , and Storage Access Key.

  • GCP - Storage Bucket.

7.

Click Save.

What to do next

Attach the profile to a policy rule set. See Rule Sets and Rule Set Groups for more information.