pcapillaryTry the prerelease
Using Pcapillary

Capture packets

Create a focused session, monitor it, search received packets, and export standard PCAP.

Start a capture

Create a focused, time-bounded session

  1. Confirm the target collector is online.
  2. Open Captures and choose a reusable profile or Create a new profile.
  3. Enter a name and whole-minute duration.
  4. Select one collector or leave All collectors when the same filter should run across the fleet.
  5. Select TCP, UDP, ICMP, or ICMP6 and optionally narrow by IP/CIDR and port or port range.
  6. Optionally mark the profile reusable, then start the capture.
Kubernetes Services

Start from cluster inventory

  1. Open Collectors and select a Kubernetes cluster.
  2. Find a Service in Cluster inventory.
  3. Choose Capture for the intended Service port.
  4. Review the prefilled protocol, port, namespace, and Service target, then start the session.

The collector follows Service, NodePort, and EndpointSlice translations visible on the host. General pod-to-pod capture is not enabled.

Monitor and stop

Watch the capture session

The sessions table shows state, owner, matched packets, deadline, and filter. Sessions stop automatically at their deadline. The owner or an administrator can stop an active session early.

Search and export

Find the packet evidence

  1. Open Packet Search.
  2. Filter by time range, capture session, collector, profile, IP address, port, or transport protocol.
  3. Run the search and expand a row to decode a packet.
  4. Use Share to copy the URL-backed search or Export PCAP to reconstruct matching packets.

Exports contain only packets matched by the current search and can be opened with Wireshark or another PCAP-compatible tool.