> Source: [sk180652](https://support.checkpoint.com/results/sk/sk180652)

# sk180652 - Missing packet captures in some IPS logs, for protections with packet capture enabled

| Property | Value |
|----------|-------|
| Solution ID | sk180652 |
| Date Created | 2023-02-22 |
| Last Modified | 2023-03-02 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- Missing packet captures in some IPS logs, for protections with packet capture enabled.

## Cause

Packet Captures are recorded only once per connection and can be associated with only one log.  
If there are multiple protections in Detect mode triggered with same pattern, only one detect log will have the packet capture attached.  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1677058970293/IPs202302221222351.jpg)

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
