Create a focused, time-bounded session
- Confirm the target collector is online.
- Open Captures and choose a reusable profile or Create a new profile.
- Enter a name and whole-minute duration.
- Select one collector or leave All collectors when the same filter should run across the fleet.
- Select TCP, UDP, ICMP, or ICMP6 and optionally narrow by IP/CIDR and port or port range.
- Optionally mark the profile reusable, then start the capture.
Start from cluster inventory
- Open Collectors and select a Kubernetes cluster.
- Find a Service in Cluster inventory.
- Choose Capture for the intended Service port.
- Review the prefilled protocol, port, namespace, and Service target, then start the session.
The collector follows Service, NodePort, and EndpointSlice translations visible on the host. General pod-to-pod capture is not enabled.
Watch the capture session
The sessions table shows state, owner, matched packets, deadline, and filter. Sessions stop automatically at their deadline. The owner or an administrator can stop an active session early.
Find the packet evidence
- Open Packet Search.
- Filter by time range, capture session, collector, profile, IP address, port, or transport protocol.
- Run the search and expand a row to decode a packet.
- Use Share to copy the URL-backed search or Export PCAP to reconstruct matching packets.
Exports contain only packets matched by the current search and can be opened with Wireshark or another PCAP-compatible tool.