# How to log alert into a pcap

**URL:** <https://forum.suricata.io/t/how-to-log-alert-into-a-pcap/2127>\
**Category:** Help\
**Created:** [January 18, 2022, 7:14am UTC](https://forum.suricata.io/t/how-to-log-alert-into-a-pcap/2127 "2022-01-18T07:14:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashokdev7](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ashokdev7/32/1143_2.png) [@ashokdev7](https://forum.suricata.io/u/ashokdev7)\
**Post date:** [January 18, 2022, 7:14am UTC](https://forum.suricata.io/t/how-to-log-alert-into-a-pcap/2127/1 "2022-01-18T07:14:39Z")

</div>

Hi  
I want to log alert/session into a pcap if a alert is triggered on a session/packet.  
How can I do it

---

<div class="post-metadata">

**Author:** ![Jeff\_Lucovsky](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/jeff_lucovsky/32/11_2.png) [@Jeff\_Lucovsky](https://forum.suricata.io/u/Jeff_Lucovsky)\
**Post date:** [January 20, 2022, 1:27pm UTC](https://forum.suricata.io/t/how-to-log-alert-into-a-pcap/2127/2 "2022-01-20T13:27:01Z")

</div>

Hi,

There is development work in progress to do this – see [Pcap conditional v2.2.12 by scottfgjordan · Pull Request #6766 · OISF/suricata · GitHub](https://github.com/OISF/suricata/pull/6766)

We expect this work to be included in Suricata 7 if it’s completed in time.

---

<div class="post-metadata">

**Author:** ![ish](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ish/32/8_2.png) [@ish](https://forum.suricata.io/u/ish)\
**Post date:** [January 21, 2022, 2:59am UTC](https://forum.suricata.io/t/how-to-log-alert-into-a-pcap/2127/3 "2022-01-21T02:59:40Z")

</div>

Until we do have that feature, the `payload` logging is quite useful. Its base64, but if you can decode it can give you a lot of extra context.

---

<div class="post-metadata">

**Author:** ![bigjohns97](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/bigjohns97/32/2171_2.png) [@bigjohns97](https://forum.suricata.io/u/bigjohns97)\
**Post date:** [July 17, 2023, 2:08pm UTC](https://forum.suricata.io/t/how-to-log-alert-into-a-pcap/2127/4 "2023-07-17T14:08:35Z")

</div>

Was about to create a thread for this feature and came across this thread, tried to track down this through the github link above but I couldn’t figure out if this made it into v7 or not.

Can someone confirm if this is available in v7 or not?

---

<div class="post-metadata">

**Author:** ![jufajardini](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/jufajardini/32/896_2.png) [@jufajardini](https://forum.suricata.io/u/jufajardini)\
**Post date:** [July 18, 2023, 5:45pm UTC](https://forum.suricata.io/t/how-to-log-alert-into-a-pcap/2127/5 "2023-07-18T17:45:56Z")

</div>

Yep, it’s there: [Suricata 7.0.0 released](https://forum.suricata.io/t/suricata-7-0-0-released/3715) 🙂
