Problem
In Wireshark, we capture all packet data for analysis. In Zeek, we summarize packet data into different kinds of log files. What are the advantages and disadvantages of recording full data (packet dump) versus metadata (parsing packet info into logs)?