Capture at the useful boundary
Choose the point that can observe both sides of the question, not merely the nearest available interface.
Traffic acquisition
Use a host tool, cloud mirror, virtual switch, SPAN, TAP, broker, or recorder to create the smallest authorized capture that contains the incident.
Start at the affected host
Use operating-system capture tools where they are available. Tool availability and permissions vary by operating system, build, and enterprise policy.
Capture at the affected host when installing Wireshark or a capture driver is not appropriate.
02Capture on the workload interface, with the smallest useful filter and incident window.
03Use the active interface and stop as soon as the reported behavior is represented.
Beyond the endpoint
A host capture is not always the best evidence. Use the cloud, hypervisor, switching, visibility, or retention layer when that gives the investigation the correct boundary.
Before you press start
PacketSafari can only investigate evidence present at the selected observation point. Encryption, asymmetric visibility, filters, slicing, packet loss, and an incomplete time window remain explicit limits.
Choose the point that can observe both sides of the question, not merely the nearest available interface.
Start just before reproduction and stop after the result. Smaller captures are easier to authorize, move, and investigate.
Use filters or packet slicing only when they will not remove payload, timing, or protocol fields required by the investigation.
Confirm authorization, retention, transfer, decryption, and sanitization requirements before sharing a capture.
Capture ready