The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

pktcapture-circular stack-node

Prev Next

This command continuously captures packets of a NS9500 and NS9600 Sensors configured in stack mode in a circular fashion until stopped. Based on the Sensor configuration, you can capture packets on a single port or in port pair.

The packets are captured by the circular buffer. The buffer size for NS9500 stack is 100MB. On reaching the end of the buffer, the oldest or starting packets in buffer are overwritten till the circular packet capture is stopped forcefully. The captured packets are saved in the /tftpboot/capture.pcap file on the Sensor. The saved file is sent to the Manager.

Note

If you have configured the Manager to send captured packets to a SPAN port, you cannot capture packets by using this command.

Syntax

To capture packets on a single port:

pktcapture-circular stack-node <stack_node_value> intfport <monitoring_port> <filter>

Parameter

Description

stack_node_value

ID of the Sensor in the stack

monitoring_port

Port for capturing incoming and outgoing packets

filter

BPF (Berkeley Packet Filter) for capturing packets. If no filter is provided, all packets are captured.

Note

If you do not want to provide a filter, use an empty string ("") as the parameter value.

Note

For high throughput devices, when capturing from the Manager, ensure filters are provided such that not more than 2 Gbps of traffic is captured.

To capture packets in port pair:

pktcapture-circular stack-node <stack_node_value> intfport-pair <monitoring_port1>-<monitoring_port2> <filter>

Parameter

Description

stack_node_value

ID of the Sensor in the stack

monitoring_port1

Port for capturing incoming packets

monitoring_port2

Port for capturing outgoing packets

filter

BPF (Berkeley Packet Filter) for capturing packets. If no filter is provided, all packets are captured.

Note

If you do not want to provide a filter, use an empty string ("") as the parameter value.

Note

For high throughput devices, when capturing from the Manager, ensure filters are provided such that not more than 2 Gbps of traffic is captured.

Applicable to:

NS9600 (stack) and NS9500 (stack)