Hi,
During analysis i noticed checkpoint threat prevention module can sometimes capture multiple packets for a specific alert (3 different packet capture unique id's) but only one pcap is available for download. It does not seem to combine all of them into one file as there's only 1 packet seen in wireshark.
Is there a setting that allows to show all pcaps in the alert, are they all the same packets so only 1 is shown in wireshark, or do you have to go directly into the server storing the pcaps and get the others from there? (Last one wouldn't be great)