Use Trends for process behavior
Attach only the signals relevant to the event and confirm every source is running. Capture a stable period before the action, the action itself, and recovery. Keep units and decoding definitions with the project so exported numbers remain interpretable.
Use Raw Traffic for protocol behavior
Record when investigating exceptions, retries, latency, unexpected function codes, or malformed responses. Filter after the capture rather than discarding surrounding frames too early; the request immediately before the failure is often relevant.
Keep a small reproducible package
Save the project after reviewing private endpoints and certificate paths. Add the native session and a short note describing expected versus actual behavior. Export CSV or a report for convenience, but keep the original session as the inspectable evidence.