Network Management

How to save a packet capture from an Orion server

This article describes how to save a packet capture from your Orion server using Wireshark.

First published date

11/12/2018 7:35 PM

Last published date

5/9/2023 5:26 AM

Overview

This article explains how to collect a packet capture from your Orion server.

Product section

Orion Platform

Cause

This is a helpful tool to identify an issue with netflow packet data

Resolution

  1. Download Wireshark from the Wireshark website

  2. Install Wireshark on your Orion server.

    • Note: When installing WireShark, do NOT let the WireShark installer install WinPcap 4.1.3 that comes with Wireshark. The Orion Platform already has a copy of WinPcap 4.1.3 installed, WireShark's installer fails to find it, and you might end up with two copies of WinPcap showing on the Apps & Features control panel.

  3. Open Wireshark to display the user interface.

  4. Click Capture and select Start.

  5. In the toolbar, click the Capture icon and select the interfaces.
     

  6. Click Launch to start the capture. 

  7. Reproduce the issue with your device.

  8. After you captured the data, click Capture > Stop to stop the network trace.

  9. Save the capture to a PCAP file.


Sending large files to SolarWinds Secure File Exchange

Files larger than 5 MB cannot be sent to emails as an attachment. Open a ticket with SolarWinds support and ask for an upload link to submit the PCAP file. Then, discuss the issue being encountered for investigation.