This behavior is by design: Threat Prevention packet captures behave in the following manner according to the current architecture:
- If the connection was blocked (action Prevent), we save only the last packet.
- If the connection continues (action Detect), we save 100kb by default (configurable).