Get Started
          Splunk Phantom adn Corelight rotating gears Splunk Phantom adn Corelight rotating gears

          A smarter way to get 100% visibility

          Smart PCAP is a highly efficient approach to packet capture that links logs, extracted files, and security insights with the packets that you need, giving you only what's necessary for investigations. This can dramatically reduce your storage costs while at the same time expanding retention times by a factor of ten. Plus, it makes working with packets far faster and easier.

          Expand your window for investigation:

          smart-pcap-timeline-mobile-02 smart-pcap-timeline-01
          smart-pcap-icons_SMART PCAP

          Capture what counts

          Stop capturing everything (like what you can't decrypt) and focus on what's critical for security operations.

          smart-pcap-icons_90 DAYS

          Months of packet retention

          With up to 10x longer retention than full PCAP you can have the packets you've always wanted and spend far less.


          One-click retrieval 

          Access packets right from your SIEM through seamless integration into logs and alerts.


          See how it works

          Tired of spending all day tracking down the packets you need?
          Watch this video to learn how one-click retrieval simplifies and speeds up the process.

          Watch the video


          Join the live webcast

          Learn more about how Smart PCAP can reduce costs while adding far more retention. Plus, see a demo of how Zeek evidence integrates Smart PCAP. Wednesday, August 25th 2021 at 10 a PST / 1p EST.

          Register now

          Make everyone an expert

          Make everyone an expert

          Watch the webinar