The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure packet capture settings in port mode

Prev Next

To configure the packet capture settings:

  1. For a standalone Sensor, select Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Packet Capturing → Capture Now.

    The Capture Now page appears.

  2. From the Send Captured Packets To drop-down list, select Monitoring (SPAN) Port.

    Note

    Configure packet capture settings in span port is not supported on a stack of NS9600 and NS9500 Sensors.

  3. Type the Capture Duration in minutes.

    Note

    Select the Run until explicitly stopped option to keep capturing for an indefinite period till you stop the capture.

    Configure SPAN port for packet capture
    Configure SPAN port for packet capture


  4. Configure the Capture Rules.

  5. Click Save to save the capture settings.

    Note

    After saving the capture settings, you can observe the timestamp using the Status field in the Capture Now window; note that the status is available only after you start a packet capture session.

  6. Click Start.

    Note

    The monitoring port should be configured in the Filter Rule before starting the capture.

    The Status displays the total number of packets that are captured.

  7. To stop the packet capture session, before the configured duration, click Stop.

  8. Click Cancel. The Sensor stops the capture and deletes the captured file.

    Note

    If file upload has started then it cannot be canceled.