Displaying the PCAP data column

The PCAP Data column is not displayed on the Log Activity tab by default. When you create search criteria, you must select the PCAP Data column in the Column Definition pane.

Before you begin

Before you can display PCAP data on the Log Activity tab, the Juniper SRX-Series Services Gateway log source must be configured with the PCAP Syslog Combination protocol. For more information about configuring log source protocols, see the Managing Log Sources Guide.

About this task

When you perform a search that includes the PCAP Data column, an icon is displayed in the PCAP Data column of the search results if PCAP data is available for an event. Using the PCAP icon, you can view the PCAP data or download the PCAP file to your desktop system.

Procedure

  1. Click the Log Activity tab.
  2. From the Search list box, select New Search.
  3. Optional. To search for events that have PCAP data, configure the following search criteria:
    1. From the first list box, select PCAP data.
    2. From the second list box, select Equals.
    3. From the third list box, select True.
    4. Click Add Filter.
  4. Configure your column definitions to include the PCAP Data column:
    1. From the Available Columns list in the Column Definition pane, click PCAP Data.
    2. Click the Add Column icon on the bottom set of icons to move the PCAP Data column to the Columns list.
    3. Optional. Click the Add Column icon in the top set of icons to move the PCAP Data column to the Group By list.
  5. Click Filter.
  6. Optional. If you are viewing events in streaming mode, click the Pause icon to pause streaming.
  7. Double-click the event that you want to investigate.

What to do next

For more information about viewing and downloading PCAP data, see the following sections: