The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Capture packets from Sensor CLI

Prev Next

You can capture incoming and outgoing packets in NS9600, NS9500, NS9x00, NS7600, NS7500, NS7x50, NS7x00, NS5x00, NS3600, NS3500, NS3200, NS3100, and Virtual IPS Sensors from the Sensor CLI. The following CLI commands are available in the Sensors that allow you to capture packets:

Note

Capturing of jumbo packet frames from the Sensor CLI is not supported in both port mode and file mode.

Note

The CLI commands mentioned are applicable only when packet capture is configured in file mode.

  • pktcapture intfport

  • pktcapture intfport-pair

  • pktcapture stack-node

  • pktcapturefile (Discard or upload captured packets to the Manager or SCP server based on the configuration.)

To capture packets continuously, the following CLI commands are available:

  • pktcapture-circular intfport

  • pktcapture-circular intfport-pair

  • pktcapture-circular stack-node

To debug various integration or connectivity issues on the management port, the CLI command pktcapture mgmt is available.

Note

The packet capture feature is mainly for troubleshooting purposes. Trellix recommends you enable it for a limited period with appropriate supervision.

Note

Trellix recommends that you ensure appropriate filters are applied when enabling packet capture. Otherwise, this can affect the Sensor performance.

These CLI commands allow you to capture packets from the Sensor CLI on an ad-hoc basis. The commands use the configuration in the Manager to determine if the captured packets should be sent to the Manager or to an SCP server. If you have configured the Manager to send captured packets to a SPAN port, you cannot capture packets by using these commands.

Note

If the Manager is in the process of capturing packets and at the same time you run this command from the Sensor CLI, the Sensor will display a message that a packet capture process is already running. Similarly, if you have started packet capture from the CLI, the Manager displays the packet capture Status as Running. In the Manager, you cannot stop a packet capture session that is started in the CLI and vice-versa. As a best practice, you should start and stop a packet capture session from the same place; either from the CLI or from the Manager.

For more information on the CLI commands, see IPS CLI Commands - Normal Mode .