I noticed that in SmartConsole while analyzing logs from the IPS module that sometimes pcap's are not available for analysis, with the following error like in the attached image:
Failed getting the incident file from the gateway. It may be expired
i found the log file for the specific event and it is present on the gateway, the alert itself shows the pcap is present and has a unique id (actual filename on the gateway) but for some reason it can't pull it on smartconsole to display for analysis.
worth noting that only some alerts show the "failed getting the incident file from the gateway", other display their pcap's just fine but i didn't notice some specific pattern, as in the time of alert has no meaning and older alerts are able to display pcaps while some newer alerts can't. What could cause this?