Using Packet Continuum, an analyst can start from the topology view / connections page to select a connection and then pivot to the global investigator interface to create a search and view packets.
The connections page has many pivot points into the global investigator interface. Each node of the Connection Graph pivots to the investigator to show all events with the selected ip as source ip or destination ip.
Once in the global investigator, users can utilize the investigator features as needed and create a search for packets.
Click through the example workflow below to see how Packet Continuum makes analysis easy.
show all events with the selected ip as source ip or destination ip.
with the selected ip as their source ip.
with the selected ip as their destination ip.
source ip and destination ip as their source ip and destination ip respectively.
as needed and create a search for packets from within the investigator as follows:
3) Click copy to copy the text.
5) Then paste and create search.
7) Click on streams to view the stream.