How to get a circular packet capture (pcap) on a Edge SWG (ProxySG)
searchcancel
How to get a circular packet capture (pcap) on a Edge SWG (ProxySG)
book
Article ID: 166431
calendar_today
Updated On: 07-15-2024
Products
ProxySG Software - SGOS
Issue/Introduction
In some troubleshooting situation there is a need of constant packet capture that would not be stopped by packet capture size limit.
Edge SWG allows to start packet capture for "last" packets or kilobytes.
Such packet capture will be running until manually stopped.
Resolution
Go to Management Console > Maintenance tab > Service Information > Packet Captures
Select "Capture last X matching Kbytes". Enter 102400 for X's value (for example)
Check Include X K Bytes in core image. Enter 102400 for X's value (for example)
Click Start Capture
*Note: The device may return an error after clicking 'Start Capture' due to exceeding the maximum acceptable value of K bytes. If this happens, please enter the maximum amount specified in the error instead of the value of '102400' as shown above.