First Analysis Workflow
Use this workflow when you are opening a capture for the first time and do not yet know which packets matter.
1. Upload and wait for open ready
Upload the .pcap, .pcapng, or .cap file from the capture library. When the
capture reaches Open ready, you can start packet review even if deeper
dashboards are still refining.
For large captures, do not wait for every background pass before you begin. Open ready means the packet list and basic analyzer surfaces are usable.
2. Check the capture summary
Start with the summary surfaces before drilling into frames:
- packet count, duration, and capture size
- protocol mix
- packet-statistics findings
- connection and endpoint summaries
- DNS and name-resolution hints when present
These views tell you whether the capture is mostly web traffic, voice/media, mail, routing, security noise, or a specialized protocol trace.
3. Open Quick Insights
Use Quick Insights for a bounded first-pass brief. Treat it as a working theory with evidence anchors, not as a final incident report.
Good first prompts from Quick Insights are usually specific:
- investigate the top issue
- show the packets behind this finding
- explain whether this is loss, latency, reset behavior, or application delay
- compare the likely client side and server side symptoms
4. Move into packets
Use the packet list and decode pane to validate the first theory:
- apply a display filter from a finding
- inspect the frame range around the first symptom
- sort or group connections by packet count, bytes, retransmissions, or status
- use protocol dashboards for DNS, TLS, RTP, or security findings when relevant
If the capture is still refining, prefer narrow filters and short frame ranges over broad scans.
5. Choose who should drive
Start Agent when you want PacketSafari to drive the next investigation step. Before starting the run, optionally open Case context and add the scenario, measurement point, appliance, or symptom. That context is passed into the Agent request and helps avoid generic conclusions.
Use Agent for:
- root-cause investigation
- explaining a failure chain
- comparing multiple candidate causes
- producing a report after a completed run
Use Copilot instead when you want to guide the investigation interactively. Stay in packets when you already know the exact filter or frame range. These control choices share the same PacketSafari Core Engine evidence.
If you start Agent from upload, choose Fast answer for a bounded urgent question, Fast + verification for useful direction followed by an independent check, or Triage then deep for capture-wide discovery before the first report. See Investigation Path Guide.
6. Save or share the result
Completed Agent runs and Quick Insights entries appear in AI Analyses. Use that view to reopen earlier findings, continue an investigation, or generate a report from an Agent run.
Minimal launch checklist
For a first SaaS evaluation, prove these flows:
- upload a small capture and open it
- read Quick Insights
- validate one finding in packets
- launch Agent from the finding or with a focused prompt
- reopen the result from AI Analyses
For suggested starter scenarios, see Demo Captures. For a concrete example of the finished workflow, read the sample Agent report.
