When trying to reconstruct a session of greater than 100 packets in the Investigation module, an error similar to the following is displayed:
This event contains <a number of packets greater than 100>. In order to reconstruct the event the number of packets processed is being limited to 100.
Packets are set to 100 by default in the UI in Reconstruction Settings.
Both the number of packets and the size of the packets in Investigator reconstruction may be increased, but should be done sparingly, as increasing this parameter may have adverse performance implications (as noted in the UI for the setting).
To make the change, follow the steps below.
Log into the Security Analytics UI as an administrative user.
Click on Administration > System, then select Investigation from the left hand navigation panel.
In the middle pane, locate Reconstruction Settings. Notice Max Packets is set to 100.