The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Starting a Packet Capture

Prev Next

To start a capture, provide the input traffic parameter and options to capture the traffic information.

Traffic Parameters

The following IP addresses, ports, and protocols are filter criteria for capture:

Parameter

Description

Host

The host IP address

Source IP

The source IP address

Destination IP

The destination IP address

Network CIDR

The masked IP address of the host

Port

The port number of the host

Source Port

The port number of the source

Destination Port

The port number of the destination

Protocol

The type of transfer protocol

You can define a combination of AND and OR conditions of rules to match specific values of the above parameters.

Additional Options

The file quantity, file size, number of packets, and names are defined for the capture.

Note

The packet capture completes after the number of packets specified is recorded.

The packet capture will not complete when the file or size limit is reached. Once the limit is reached, the files are overwritten with the latest packets. You can stop the capture manually.

You can run only one capture at a time. Refer to Starting a Packet Capture using the Web UI to run a packet capture.