PacketSafari

First Analysis Workflow

A short path from uploaded PCAP to first evidence, packet review, and an optional AI investigation.

Use this workflow when you are opening a capture for the first time and do not yet know which packets matter.

1. Upload and wait for open ready

Upload the .pcap, .pcapng, or .cap file from the capture library. When the capture reaches Open ready, you can start packet review even if deeper dashboards are still refining.

For large captures, do not wait for every background pass before you begin. Open ready means the packet list and basic analyzer surfaces are usable.

2. Check the capture summary

Start with the summary surfaces before drilling into frames:

  • packet count, duration, and capture size
  • protocol mix
  • packet-statistics findings
  • connection and endpoint summaries
  • DNS and name-resolution hints when present

These views tell you whether the capture is mostly web traffic, voice/media, mail, routing, security noise, or a specialized protocol trace.

3. Open Upload Insights

Use Upload Insights for deterministic capture readiness, processing state, and bounded packet evidence. It is an orientation surface, not an AI-generated theory or final incident report.

Good first pivots from Upload Insights are usually specific:

  • open the packets behind a finding
  • inspect the connection or frame range attached to the evidence
  • ask Copilot a focused question about loss, latency, resets, or application delay
  • start an Agent investigation when the evidence needs autonomous follow-through

4. Move into packets

Use the packet list and decode pane to validate the first theory:

  • apply a display filter from a finding
  • inspect the frame range around the first symptom
  • sort or group connections by packet count, bytes, retransmissions, or status
  • use protocol dashboards for DNS, TLS, RTP, or security findings when relevant

If the capture is still refining, prefer narrow filters and short frame ranges over broad scans.

5. Choose who should drive

Start Agent when you want PacketSafari to drive the next investigation step. Before starting the run, optionally open Case context and add the scenario, measurement point, appliance, or symptom. That context is passed into the Agent request and helps avoid generic conclusions.

Use Agent for:

  • root-cause investigation
  • explaining a failure chain
  • comparing multiple candidate causes
  • producing a report after a completed run

Use Copilot instead when you want to guide the investigation interactively. Stay in packets when you already know the exact filter or frame range. These control choices share the same PacketSafari Core Engine evidence.

If you start Agent from upload, choose Fast answer for a concrete bounded urgent question or focused starting point, Fast + verification for a concrete question that needs early direction plus later capture-wide final adjudication, or Triage then report as the preset-only broad path. See Investigation Path Guide.

6. Save or share the result

Completed Agent runs and Copilot chats appear in AI Analyses. Use that view to reopen earlier AI work or continue an investigation. Upload Insights stays with the capture's deterministic processing and evidence state.

Minimal launch checklist

For a first SaaS evaluation, prove these flows:

  • upload a small capture and open it
  • read Upload Insights
  • validate one finding in packets
  • launch Agent from the finding or with a focused prompt
  • reopen the result from AI Analyses

For suggested starter scenarios, see Demo Captures. For a concrete example of the finished workflow, read the sample Agent report.