Multi-cloud and regional cloud investigation
Keep Oracle, Alibaba, and regional cloud controls. Use one evidence workflow.
Oracle Cloud, Alibaba Cloud and European providers expose different combinations of flow logs, audit events, traffic mirroring and workload access. PacketSafari provides a consistent investigation layer once an authorized PCAP has been acquired.
Host workloads, provide virtual networking, enforce cloud policy, and expose provider-specific logs, metrics, audit trails, and visibility features.
Prefer native mirroring when documented. Otherwise use host capture, a virtual TAP or sensor, a network appliance, Kubernetes capture, or an existing recorder inside the authorized customer boundary.
Normalize the investigation workflow after acquisition: map the PCAP, test the question, verify the conclusion, and hand over reviewable evidence.
Representative products
Different jobs. One clean handoff.
These are representative ecosystem products, not partner badges or certification claims. Capabilities and packet access vary by edition, license, deployment, and configuration.
Virtual traffic mirroring for VNIC and load-balancer paths
Copies filtered traffic to a collector for full-packet capture.
Strong handoffUse the VTAP collector to create the bounded PCAP PacketSafari investigates.
Network-flow metadata and accept/reject context
Flow records rather than packet contents.
ComplementaryScope the VCN, VNIC, peers, ports, and incident window before capture.
Filtered ENI traffic mirroring over VXLAN
Copies packets to a collector ENI, load balancer, or GWLB endpoint.
Strong handoffCreate a PCAP at the collector and investigate the selected incident window.
Flow metadata, audit events, metrics, and operational scope
Context and connection metadata; not a raw packet capture.
ComplementaryUse provider context to identify what, where, and when to capture.
European public-cloud compute and private networking
Confirm native visibility for the selected service; host or virtual-sensor capture may be required.
Architecture-dependentKeep packet processing within the approved European or customer-controlled boundary.
European cloud compute, private networks, and containers
Capture may be taken from the workload, node, cluster, or approved virtual appliance.
Architecture-dependentApply the same PCAP investigation workflow without assuming AWS-style mirroring.
European cloud compute and private networking
Workload or virtual-sensor capture is the conservative acquisition path.
Architecture-dependentInvestigate locally acquired PCAPs while preserving residency requirements.
European sovereign-oriented cloud networking
Use documented flow visibility where available and capture from an authorized workload or sensor for PCAP.
Architecture-dependentMaintain a consistent evidence output across regulated cloud environments.
European cloud compute and private networking
Host, appliance, or cluster capture may be required for raw packet evidence.
Architecture-dependentBring the resulting bounded PCAP into a repeatable investigation workflow.
Distributed compute, networking, and Kubernetes
Use workload, node, or approved sensor capture when raw packets are required.
Architecture-dependentSeparate cloud acquisition from PacketSafari analysis and reporting.
Decision guide
Use each layer for the decision it owns.
PacketSafari adds depth after a capture exists. It does not become the continuous monitor, enforcement point, access broker, packet broker, or recorder.
Does the provider offer native traffic mirroring?
Use it when the source, destination, region, performance, and policy constraints fit the incident.
Is only flow metadata available?
Use it to scope the question, then capture at the workload, node, appliance, or adjacent authorized boundary.
Does the client require European or sovereign processing?
Run the capture and PacketSafari deployment path inside the approved region or customer-controlled environment.

