The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

show pktcapture status

Prev Next

This CLI command displays the packet capture status and configuration.

Note

If you observe any errors or memory leaks in the show pktcapture status command output, you must tune the packet capture filters. If the Frontend Packet Capture Mbuf Clone Error Cnt is non-zero and increasing, you must reboot the Sensor.

Syntax:

show pktcapture status

Sample Output:

Normal mode:

IntruShell@Test-Sensor#> show pktcapture status

Packet Capture Status :Not Running

Send Captured Packets To :Manager

Packet Capture Rule Set File Status :Present

Packet Capture File Status :PCAP File Not Present

Total Packet Capture Count :0

File Max Size :100 MB

Debug mode:

IntruDbg#> show pktcapture status

Packet Capture Status :Running

Send Captured Packets To :Manager

Packet Capture Rule Set File Status :Not Present

Packet Capture File Status :PCAP File Not Present

Datapath 0 :

l7ae Egress matched pkt sent cnt :13693

l7ae Egress pkt clone err cnt :0

l7ae Egress pkt chain err cnt :0

l7ae Egress pkt capture enable cnt :0

l7ae Egress pkt capture disable cnt :0

l7ae Egress Jumbo pkt skip cnt :0

.....

Datapath 15 :

l7ae Egress matched pkt sent cnt :171626

l7ae Egress pkt clone err cnt :0

l7ae Egress pkt chain err cnt :0

l7ae Egress pkt capture enable cnt :0

l7ae Egress pkt capture disable cnt :0

l7ae Egress Jumbo pkt skip cnt :0

Across All datapaths

l7ae Egress matched pkt sent cnt :1788707

l7ae Egress pkt clone err cnt :0

l7ae Egress pkt chain err cnt :0

l7ae Egress Jumbo pkt skip cnt :0

Frontend Egress Matched Pkt Sent Cnt :174147703

Frontend Ingress Matched Pkt Sent Cnt :175939455

Frontend Ingress Pkt Capture Jumbo Frames Skip Cnt :0

Frontend Egress Pkt Capture Jumbo Frames Skip Cnt :0

Frontend Packet Capture Mbuf Clone Error Cnt :0

Frontend Packet Capture Mbuf Chain Error Cnt :0

Frontend Packet Capture Enable Count :0

Frontend Packet Capture Disable Count :0

Total Packet Capture Count :327136912

File Max Size :100 MB

This command displays the following additional counters in debug mode:

  • l7ae Egress matched pkt sent cnt - Number of matched incoming packets that are sent from each backend processor to the packet capture process

  • l7ae Egress pkt clone err cnt - Number of clone errors for outgoing packets on each backend processor

  • l7ae Egress pkt chain err cnt - Number of mbuf chain errors encountered for outgoing packets

  • l7ae Egress pkt capture enable cnt - Number of times the packet capture filter is applied for each backend processor

  • l7ae Egress pkt capture disable cnt - Number of times the packet capture filter is removed from each backend processor

  • Frontend Ingress Matched Pkt Sent Cnt - Number of matched incoming packets that are sent to packet capture process from frontend processor

  • Frontend Egress Matched Pkt Sent Cnt - Number of matched outgoing packets sent to packet capture process from frontend processor

  • Frontend Packet Capture Mbuf Clone Error Cnt - Number of mbuf clone errors

  • Frontend Packet Capture Mbuf Chain Error Cnt - Number of mbuf chain error

  • Frontend Packet Capture Enable Count - Number of times the packet capture filter is applied for frontend processor

  • Frontend Packet Capture Disable Count - Number of times the packet capture filter is removed from frontend processor

Applicable to:

NS-series Sensors