Investigation Path Guide

Choose between Fast answer, Fast + verification, and Triage then deep without mixing analysis depth, operator control, privacy, or report delivery.

PacketSafari separates time to useful direction from time to a defensible root-cause analysis. A focused Agent can begin before the wider capture is fully processed, while the PacketSafari Core Engine continues protocol decoding, indexing, rule evaluation, correlation, and bounded evidence retrieval.

The right path depends on the incident. The evidence standard does not: material conclusions should remain tied to inspectable frames, filters, streams, timestamps, decoded fields, and capture viewpoints.

For the customer-facing visual explanation, see PCAP Investigation Workflows.

Compare the analysis workflows

WorkflowFirst resultPacketSafari Core EngineFollow-upBest forMain tradeoff
Fast answerOne clearly labelled preliminary report as soon as the capture is safely readable.PacketSafari Triage is optional and can continue after the first result.No automatic independent verification follow-up.Urgent, bounded questions with a known IP, Call-ID, hostname, stream, protocol, or time range.It may miss correlations and competing evidence elsewhere in the capture.
Fast + verificationA focused preliminary report while PacketSafari Triage processes the wider capture.Indexing, rules, ranking, and correlation continue in the background.A related verifier adopts, qualifies, contradicts, or leaves each strong candidate inconclusive.Operational incidents that need useful direction now and a defensible report afterward.Verification finishes on a separate clock and consumes the deeper workflow stage.
Triage then deepThe first Agent report waits for indexed context.Capture-wide rules, protocol signals, priority flows, and correlations are prepared first.One deep report starts from the strongest available indexed context.Large or unfamiliar captures where the issue may be sparse and no reliable selector is known.Slowest time to the first report.

Fast + verification is the normal recommended path for eligible Agent plans. For captures of 5 MB or more, the upload flow asks for a focused starting point. When no reliable selector is known, choose capture-wide discovery; PacketSafari recommends Triage then deep because indexed evidence discovery is more likely to matter. At this size, Fast answer remains available only with a focused starting point.

Provide a selector when you have one

A selector helps the early Agent stay bounded and useful:

  • IP address or port
  • Call-ID or phone number
  • hostname or BSSID
  • TCP or UDP stream
  • protocol and known error
  • time range around the reported symptom

A selector focuses the preliminary investigation. It does not prevent the later verifier from checking the wider capture in Fast + verification.

Choose the question separately

The upload prompt describes what PacketSafari should answer:

  • Executive summary for the main flows, problems, and next actions
  • Root cause for the dominant failure family and its packet proof
  • Security review for suspicious behavior and escalation-worthy findings
  • Custom prompt for a specific operator or report question

Any of these questions can use the analysis workflow appropriate to the incident. A root-cause prompt is not automatically a deep workflow, and a custom prompt is not automatically a fast workflow.

Choose who drives separately

  • Inspect manually when you want direct control of filters, packet decode, streams, statistics, and specialist dashboards.
  • Copilot guided when you want an interactive, capture-aware investigation and expect to refine the question through follow-ups.
  • Agent investigation when you want PacketSafari to plan, test, correlate, and report against packet evidence.

All three can use the same PacketSafari Core Engine facts. They describe the operator-control model rather than the processing-depth workflow.

Privacy and delivery are cross-cutting controls

Anonymize before upload creates a sibling capture and runs the selected Agent workflow on that anonymized copy. It is a privacy choice, not an analysis mode.

Where report email is configured and permitted:

  • Fast answer can send the preliminary report.
  • Fast + verification can send the preliminary report first and the exact verification outcome later.
  • Triage then deep can send its completed deep report.

The verification email must say whether the outcome is verified, partially verified, inconclusive, or contradicted. Indexing progress should not create an email flood.

Runtime and large-capture qualification

For validated Teams and enterprise deployment profiles, an evidence-backed preliminary report within roughly two minutes after durable upload/safe-open for a focused single capture up to 1 GiB is a product validation target. It is not a universal current guarantee and does not include network upload time.

Upload transfer, queueing, safe-open, preliminary analysis, indexing, and verification completion have separate clocks. Larger accepted-capture profiles also do not imply the same RCA runtime; protocol mix, packet count, capture structure, question, concurrency, storage, and infrastructure all matter.