Previous Topic: Incident Responses - Email NotificationNext Topic: Incident Responses - Performance via SNMP Investigation


Incident Responses - Packet Capture Investigation

Use a Packet Capture investigation to perform a filtered capture of the particular server, application port, and network experiencing a problem. Use the Duration and Severity options to filter temporary incident conditions.

Frequently Asked Questions

Property Details

Complete the following fields:

Minimum Conditions for Taking Action

Specify the minimum severity and duration required for the management console to launch the responsive action. Both criteria must be met for the management console to launch the responsive action.

Severity

Choose an option to specify the incident severity that is required for the management console to launch the responsive action:

  • Minor
  • Major
  • Unavailable
Duration

Choose a threshold, in minutes, for the consecutive amount of time that the same Network or Server metric threshold must be violated for the management console to launch the responsive action.

For example, if Network Round Trip Time (NRTT) is Minor at 1:20, the management console opens a network incident. If NRTT is Minor again at 1:25, and the Duration for the responsive action is 10 minutes, the management console can launch the responsive action.

Packet Capture Options
Capture Period

Capture period of from 30 seconds to 30 minutes. The default is 5 minutes.

Maximum File Size

When capturing packets with a CA Standard Monitor, choose a maximum file size between 10 MB and 100 MB.

This option is not applicable when the packets are captured by a NI GigaStor or CA Multi-Port Monitor.

Bytes Per Packet

When capturing packets with a CA Standard Monitor, specify the number of bytes per packet to capture. Choose between Header Only and 8192 bytes. Note that Header Only captures the MAC (Layer 2), IP (Layer 3), and TCP (Layer 4) header information.

This option is not applicable when the packets are captured by a NI GigaStor or CA Multi-Port Monitor.

More information:

How Incident Responses Work

Secure Packet Capture Investigation Files