First Analysis Workflow
Use this workflow when you are opening a capture for the first time and do not yet know which packets matter.
1. Upload and wait for open ready
Upload the .pcap, .pcapng, or .cap file from the capture library. When the
capture reaches Open ready, you can start packet review even if deeper
dashboards are still refining.
For large captures, do not wait for every background pass before you begin. Open ready means the packet list and basic analyzer surfaces are usable.
2. Check the capture summary
Start with the summary surfaces before drilling into frames:
- packet count, duration, and capture size
- protocol mix
- packet-statistics findings
- connection and endpoint summaries
- DNS and name-resolution hints when present
These views tell you whether the capture is mostly web traffic, voice/media, mail, routing, security noise, or a specialized protocol trace.
3. Open Upload Insights
Use Upload Insights for deterministic capture readiness, processing state, and bounded packet evidence. It is an orientation surface, not an AI-generated theory or final incident report.
Good first pivots from Upload Insights are usually specific:
- open the packets behind a finding
- inspect the connection or frame range attached to the evidence
- ask Copilot a focused question about loss, latency, resets, or application delay
- start an Agent investigation when the evidence needs autonomous follow-through
4. Move into packets
Use the packet list and decode pane to validate the first theory:
- apply a display filter from a finding
- inspect the frame range around the first symptom
- sort or group connections by packet count, bytes, retransmissions, or status
- use protocol dashboards for DNS, TLS, RTP, or security findings when relevant
If the capture is still refining, prefer narrow filters and short frame ranges over broad scans.
5. Choose who should drive
Start Agent when you want PacketSafari to drive the next investigation step. Before starting the run, optionally open Case context and add the scenario, measurement point, appliance, or symptom. That context is passed into the Agent request and helps avoid generic conclusions.
Use Agent for:
- root-cause investigation
- explaining a failure chain
- comparing multiple candidate causes
- producing a report after a completed run
Use Copilot instead when you want to guide the investigation interactively. Stay in packets when you already know the exact filter or frame range. These control choices share the same PacketSafari Core Engine evidence.
If you start Agent from upload, choose Fast answer for a concrete bounded urgent question or focused starting point, Fast + verification for a concrete question that needs early direction plus later capture-wide final adjudication, or Triage then report as the preset-only broad path. See Investigation Path Guide.
6. Save or share the result
Completed Agent runs and Copilot chats appear in AI Analyses. Use that view to reopen earlier AI work or continue an investigation. Upload Insights stays with the capture's deterministic processing and evidence state.
Minimal launch checklist
For a first SaaS evaluation, prove these flows:
- upload a small capture and open it
- read Upload Insights
- validate one finding in packets
- launch Agent from the finding or with a focused prompt
- reopen the result from AI Analyses
For suggested starter scenarios, see Demo Captures. For a concrete example of the finished workflow, read the sample Agent report.
