As an analyst, I need to be able to pivot on ICMP alerts or metadata and retrieve packets. Current support is TCP and UDP.
An analyst could use the ability to filter the pcap view to one side of the conversation, i.e. client or server (leaving both as default), to optimize their pcap analysis....
The Hunt pivot on a missing field (from a multi-field aggregation) does not produce a useful search. For example, if the network.protocol field displayed "*Missing", pivots on the field would...
An analyst could use additional pivots on a number field in Hunt: \> < maybe >= and