This CLI command displays the packet capture status and configuration.
Note
If you observe any errors or memory leaks in the
show pktcapture statuscommand output, you must tune the packet capture filters. If theFrontend Packet Capture Mbuf Clone Error Cntis non-zero and increasing, you must reboot the Sensor.
Syntax:
show pktcapture status
Sample Output:
Normal mode:
IntruShell@Test-Sensor#> show pktcapture status
Packet Capture Status :Not Running
Send Captured Packets To :Manager
Packet Capture Rule Set File Status :Present
Packet Capture File Status :PCAP File Not Present
Total Packet Capture Count :0
File Max Size :100 MB
Debug mode:
IntruDbg#> show pktcapture status
Packet Capture Status :Running
Send Captured Packets To :Manager
Packet Capture Rule Set File Status :Not Present
Packet Capture File Status :PCAP File Not Present
Datapath 0 :
l7ae Egress matched pkt sent cnt :13693
l7ae Egress pkt clone err cnt :0
l7ae Egress pkt chain err cnt :0
l7ae Egress pkt capture enable cnt :0
l7ae Egress pkt capture disable cnt :0
l7ae Egress Jumbo pkt skip cnt :0
.....
Datapath 15 :
l7ae Egress matched pkt sent cnt :171626
l7ae Egress pkt clone err cnt :0
l7ae Egress pkt chain err cnt :0
l7ae Egress pkt capture enable cnt :0
l7ae Egress pkt capture disable cnt :0
l7ae Egress Jumbo pkt skip cnt :0
Across All datapaths
l7ae Egress matched pkt sent cnt :1788707
l7ae Egress pkt clone err cnt :0
l7ae Egress pkt chain err cnt :0
l7ae Egress Jumbo pkt skip cnt :0
Frontend Egress Matched Pkt Sent Cnt :174147703
Frontend Ingress Matched Pkt Sent Cnt :175939455
Frontend Ingress Pkt Capture Jumbo Frames Skip Cnt :0
Frontend Egress Pkt Capture Jumbo Frames Skip Cnt :0
Frontend Packet Capture Mbuf Clone Error Cnt :0
Frontend Packet Capture Mbuf Chain Error Cnt :0
Frontend Packet Capture Enable Count :0
Frontend Packet Capture Disable Count :0
Total Packet Capture Count :327136912
File Max Size :100 MB
This command displays the following additional counters in debug mode:
l7ae Egress matched pkt sent cnt - Number of matched incoming packets that are sent from each backend processor to the packet capture process
l7ae Egress pkt clone err cnt - Number of clone errors for outgoing packets on each backend processor
l7ae Egress pkt chain err cnt - Number of mbuf chain errors encountered for outgoing packets
l7ae Egress pkt capture enable cnt - Number of times the packet capture filter is applied for each backend processor
l7ae Egress pkt capture disable cnt - Number of times the packet capture filter is removed from each backend processor
Frontend Ingress Matched Pkt Sent Cnt - Number of matched incoming packets that are sent to packet capture process from frontend processor
Frontend Egress Matched Pkt Sent Cnt - Number of matched outgoing packets sent to packet capture process from frontend processor
Frontend Packet Capture Mbuf Clone Error Cnt - Number of mbuf clone errors
Frontend Packet Capture Mbuf Chain Error Cnt - Number of mbuf chain error
Frontend Packet Capture Enable Count - Number of times the packet capture filter is applied for frontend processor
Frontend Packet Capture Disable Count - Number of times the packet capture filter is removed from frontend processor
Applicable to:
NS-series Sensors