The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

pktcapture-circular intfport

Prev Next

This command continuously captures both incoming and outgoing packets of a monitoring port that match the specified criteria in a circular fashion until stopped. If you have configured the Sensor to receive and send traffic on a single port, you can use this command to capture packets.

The packets are captured by the circular buffer. The circular buffer size varies based on the NS-series or Virtual IPS Sensor. For example, the buffer size for NS9100 is 100MB, the buffer size for VM600 is 58 MB, etc. On reaching the end of the buffer, the oldest or starting packets in buffer are overwritten till the circular packet capture is stopped forcefully. The captured packets are saved in the /tftpboot/capture.pcap file on the Sensor. The saved file is sent to the Manager.

Note

If you have configured the Manager to send captured packets to a SPAN port, you cannot capture packets by using this command.

Syntax:

pktcapture-circular intfport <monitoring_port> <filter>

Parameter

Description

monitoring_port

Port for capturing incoming and outgoing packets.

Note

For NS series Sensors (except NS3600, NS3500, and NS3x00), the monitoring ports will be in the format "gx/(x or y)". For NS3600, NS3500, and NS3x00 Sensors, the monitoring ports will be in the format "x". For Virtual IPS Sensors, the monitoring ports will be in the format "x".

filter

BPF (Berkeley Packet Filter) for capturing packets. If no filter is provided, all packets are captured.

Note

If you do not want to provide a filter, use an empty string ("") as the parameter value.

Note

For high throughput devices, when capturing from the Manager, ensure filters are provided such that not more than 2 Gbps of traffic is captured.

Sample Output:

intruShell@NS7350-101> pktcapture-circular intfport g1/1 ""

A packet capture file will be sent to the Manager, as per the configuration.

Do you want to proceed with the packet capture session?

Please enter Y to confirm: Y

pktcapture: capture all...

Applicable to:

NS9600 (standalone), NS9500 (standalone), NS9x00, NS7600, NS7500, NS7x50, NS7x00, NS5x00, NS3600, NS3500, NS3x00 series, and Virtual IPS Sensors.