I may just have to use content filters. I avoided it because I do not know what metadata is excluded. I am specifically trying to get flow-based data, including IPs, port, protocol, flags, and the length of the payload (not payload data itself). Would I be able to access all of that with the content filter?
Topic:
App & System Services
SubTopic:
Networking
Tags: