The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

pktcapture stack-node

Prev Next

This command captures packets of NS9500 and NS9600 Sensors configured in stack mode. Based on the Sensor configuration, you can capture packets on a single port or in port pair.

The captured packets are saved in the /tftpboot/capture.pcap file on the Sensor. The saved file is sent to the Manager or a SCP server based on the configuration made in the Manager. If you have configured the Manager to send captured packets to a SPAN port, you cannot capture packets by using this command.

Note

You can capture packets from the Manager as well. If the Manager is in the process of capturing packets, and at the same time, you run this command, the Sensor will display a message that a packet capture process is already running. Similarly, if you have started packet capture from the CLI, the Manager displays the packet capture Status as Running. In the Manager, you cannot stop a packet capture session that is started in the CLI and vice-versa. As a best practice, you should start and stop a packet capture session from the same place: either from the CLI or from the Manager.

Syntax

To capture packets on a single port:

pktcapture stack-node <stack_node_value> intfport <monitoring_port> <filter>

Parameter

Description

stack_node_value

ID of the Sensor in the stack

monitoring_port

Port for capturing incoming and outgoing packets

filter

BPF (Berkeley Packet Filter) for capturing packets. If no filter is provided, all packets are captured.

Note

If you do not want to provide a filter, use an empty string ("") as the parameter value.

Note

For high throughput devices, when capturing from the Manager, ensure filters are provided such that not more than 2 Gbps of traffic is captured.

To capture packets in port pair:

pktcapture stack-node <stack_node_value> intfport-pair <monitoring_port1>-<monitoring_port2> <filter>

Parameter

Description

stack_node_value

ID of the Sensor in the stack

monitoring_port1

Port for capturing incoming packets

monitoring_port2

Port for capturing outgoing packets

filter

BPF (Berkeley Packet Filter) for capturing packets. If no filter is provided, all packets are captured.

Note

If you do not want to provide a filter, use an empty string ("") as the parameter value.

Note

For high throughput devices, when capturing from the Manager, ensure filters are provided such that not more than 2 Gbps of traffic is captured.

Applicable to:

NS9600 (stack) and NS9500 (stack)