Created on
10-03-2024
12:56 AM
Edited on
10-03-2024
06:29 AM
By
Jean-Philippe_P
Description | This article describes how to set packet capture (PCAP) files to download from FortiAnalyzer encrypted and/or in ZIP format. This feature has been added to FortiAnalyzer Starting from release v7.4.1. |
Scope | FortiAnalyzer/FortiManager (FortiAnalyzer Feature enabled). |
Solution |
config system log pcap-file set download-modezip-with-password{plain | zip | zip-with-password} <----- Alternative options. end
The file is downloaded and the password is displayed in the FortiAnalyzer GUI. Copy the password, as needed to decrypt the archived Zip file.
To unlock the downloaded file, the previously saved password must be used.
Note: Archive contents should be enabled in FortiGate to reflect on FortiAnalyzer logs. Related article: Technical Note: How to archive content of all emails passing through a FortiGate |