The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

show flows

Prev Next

This command displays how many flows exist in the current traffic.

This command has no parameters.

Syntax:

show flows

Information displayed by the show flows command are as follows:

  • Total TCBs

  • Total free TCBs

  • Total active TCP flows

  • Total TCP flows in timewait

  • Total active UDP flows

  • Total flows in SYN state

  • Total TCP flows created

  • Total abandoned TCP handshakes

  • syncookie inbound status

  • syncookie outbound status

  • Total syn cookie proxy connections

  • Total dequote flows count

In addition to the above mentioned information, this command displays the following information when executed in debug mode of NS-series Sensors:

  • Total in-use CB Hash Buckets found

  • Total invalid CB Hash Buckets found

  • CB Syn List status

  • CB Free List status

Sample Output:

intruShell@john> show flows

Total TCBs = 88612

Total free TCBs = 88609

Total active TCP flows = 3

Total TCP flows in timewait = 0

Total active UDP flows = 20

Total flows in SYN state = 1

Total TCP flows created = 15944

Total abandoned TCP handshakes = 302

syncookie inbound status = Inactive

syncookie outbound status = Inactive

Total syn cookie proxy connections = 0

Total dequote flows count = 20

Applicable to:

NS-series Sensors