Forensics recovery
To retrieve raw packet capture data from packet capture devices, run a forensics
recovery job on one or more IP addresses or ports.
Running a recovery on an IP address or port
Run a forensics recovery to retrieve the raw capture data from the capture device.
You can run a recovery on multiple IP addresses or ports. If you don't enter an IP
address or port, all TCP and UDP traffic is recovered. If you enter multiple IP
addresses or ports, you must use a comma to separate them.
Run a forensics recovery by right clicking on an IP address or port in QRadar, or
by selecting the Run recovery icon
on the Forensics tab.
Do'stlaringiz bilan baham: |