The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

pktcapture mgmt

Prev Next

This command filters and captures packets of the management port. This command is used to debug various integration or connectivity issues on the Management port.

Syntax:

pktcapture mgmt <filter>

Parameter

Description

filter

BPF (Berkeley Packet Filter) for capturing packets. If no filter is provided, all packets are captured.

Note

If you do not want to provide a filter, use an empty string ("") as the parameter value.

Note

For high throughput devices, when capturing from the Manager, ensure filters are provided such that not more than 2 Gbps of traffic is captured.

Sample Output:

intruShell@NS7350> pktcapture mgmt "port 22"

A packet capture file will be sent to the Manager, as per the configuration.

Do you want to proceed with the packet capture session?

Tip: Press "ctrl+k" to terminate a packet capture session.

Please enter Y to confirm: Y

09:42:57.698177 IP 10.20.24.24.5137 > 10.1.1.8.22: Flags [S], seq 2072890780, win 64960, options [mss 1160,nop,wscale 8,nop,nop,sackOK], length 0

09:42:57.698232 IP 10.213.171.81.22 > 10.20.24.24.5137: Flags [S.], seq 2938926341, ack 2072890781, win 29200, options [mss 1460], length 0

09:42:57.725049 IP 10.20.24.24.5137 > 10.1.1.8.22: Flags [.], ack 1, win 64960, length 0

Applicable to:

NS9600 (standalone and stack), NS9500 (standalone and stack), NS9x00, NS7600, NS7500, NS7x50, NS7x00, NS5x00, NS3600, NS3500, NS3x00 series, and Virtual IPS Sensors.