Products
Applications
Support
Company
How To Buy
Skip to main content (Press Enter).
Sign in
Skip auxiliary navigation (Press Enter).
Register
Skip main navigation (Press Enter).
Toggle navigation
Search Options
Home
My Communities
Communities
All Communities
Application Networking and Security
Enterprise Software
Mainframe Software
Software Defined Edge
Symantec Enterprise
Tanzu
VMware Cloud Foundation
Blogs
All Blogs
Enterprise Software
Mainframe Software
Symantec Enterprise
VMware
Events
All Events
Enterprise Software
Mainframe Software
Symantec Enterprise
VMware
Water Cooler
Betas
Flings
Education
Groups
Enterprise Software
Mainframe Software
Symantec Enterprise
VMware
Members
Blog Viewer
How to Collect a Wireshark Capture
By
CB_Support
posted
Mar 27, 2019 10:04 PM
0
Recommend
Environment
Wireshark: All Supported Versions
Microsoft Windows: All Supported Versions
Objective
To collect a Wireshark capture for network connectivity issues
Resolution
Download and install Wireshark
. (Npcap is required to record live traffic)
Open Wireshark and navigate to Edit > Preferences > Protocols > HTTP
Add the SSL Port (i.e., Sensor/Agent port) used depending on the product.
Save the options > navigate back to the main Wireshark window > double-click on the appropriate network connection to start recording.
After 5-10 minutes of capturing network activity while reproducing the issue, stop the capture and save the capture as: {devicename}.pcapng
Zip the file. and
upload the Vault
.
Comment on the case that the data has been uploaded to CB Vault.
Additional Notes
A PCAP is not requested by Support as a first step in resolving a communication issue, unless absolutely necessary.
This can be used as supplemental data for troubleshooting Sensor/Backend or Agent/Server, SSL, and quarantine communication.
Related Content
App Control: How to Test Agent Network Connectivity (Windows)
Carbon Black Cloud: How To Troubleshoot Sensor Communication Issues
App Control: How to Collect Wireshark Captures for Support Cases
Carbon Black Cloud: How to Get Started With Quarantine Mode
Wireshark · Download
#EndpointStandard
#AppControl
#EDR
#CarbonBlackCloud
#EnterpriseEDR
0 comments
1 view
Permalink
Copyright 2019. All rights reserved.
Powered by Higher Logic