Under Artifact Collection
section of the web app, navigate to PCAP Collection rules
and click Add Rule
.
Create a PCAP collection rule to automate collection of network captures from Linux sensors based on specific file patterns and sensor platform / tags.
After a short while after saving, you should start to see the PCAPs show up in the Artifacts Section of the web app.