You can download attack packets captured by SRX Series devices and analyze these packets externally using tools such as Wireshark, tcpdump, tshark, and so on.
To download the attack packets:
Note: The Download PCAP menu is enabled only if the Event Category is IPS.
Note: PCAPs can be suppressed by the log suppression mechanism, which is enabled by default. To disable log suppression, see suppression. To configure SRX IDP packet capture, see Configuring Security Packet Capture.
© 2018 Juniper Networks, Inc. All rights reserved