Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Get pcap data file via API

Hi experts,

I have a question about API capability for pcap file.

I want to deploy the following workflow system.

  1, Firepower filter and capture malformed packets in accordance with IPS rule.

  2, Firepower management center sends syslog alert to SIEM system about the filtering or capturing.

  3, The SIEM gets the pcap file that related to the syslog alert via API.


Does firepower management center support the API to get pcap file?


Kenjiro Kanemaki

Cisco Employee

There two ways I know of to

There two ways I know of to obtain the PCAP for a specific Snort (IDS/IPS) event.

1. Request packets through the eStreamer API.  You'll get all the packets all the time.  It is possible to request a specific PCAP through estreamer but I'm not entirely sure how thats done. Arcsight does using the timestamp for the Snort event but this approach is prone to error (see no.2).

2. Using the JDBC interface you can request a packet using Timestamp, Event ID and device name from the Snort event.  This tuple of information assures that you'll get _the_ correct packet and is a better way to implement option 1.

New Member

Thank you very much for your

Thank you very much for your quick answer! I'll consider it with the two ways.