I was faced with a difficult situation where I had to find a why a SentinelOne agent will not communicate with the management portal for some reason. I ran the troubleshooting script which generated many files and among them there was a packet captured file as we can see below:
We can use the etl2pcapng.exe
to convert the log files into the pcap file. The executable for the application is in the reference section