Reference

CLI Reference

471 commands across 49 groups, generated straight from ze help command --json -- the same live command registry the binary itself uses, including the pipe operators available to each command. Full machine-readable list: data/cli-commands.json.

Pipes

Pipe operators

Each command row names the operators it accepts after |. Availability comes from the live command registry: operators may require row data, a streaming answer, or expansion by the operator's local process.

Operator reference 17
OperatorClassAvailableDescription
jsonOutput and controlAlwaysJSON output
ndjsonOutput and controlAlwaysOne JSON object per line
tableOutput and controlAlwaysRender as table
textOutput and controlAlwaysSpace-aligned columns
yamlOutput and controlAlwaysYAML output
rawOutput and controlAlwaysDispatcher JSON, unformatted
no-moreOutput and controlAlwaysDisable paging
logStreamingWhile streamingAppend each update instead of replacing it, where the command keeps answering
saveOutput and controlAlways, Local process onlyWrite the answer to a file
matchRow dataAlways, With rowsKeep the rows holding this text
countRow dataAlways, With rowsCount the rows
firstRow dataAlways, With rowsTake first N rows
lastRow dataAlways, With rowsTake last N rows
displayRow dataAlways, With rowsAnswer with these fields, in this order
fillRow dataAlways, With rowsBring the remaining columns back, in the command's order or a named one
resolveRow dataAlwaysReverse DNS for IP addresses
originRow dataAlwaysASN and network for IP addresses
clear l2tp 4
CommandModeDescriptionPipes
clear l2tp session allDaemonDisconnect every L2TP session on this box.
clear l2tp session all
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear l2tp session idDaemonDisconnect one subscriber session.
clear l2tp session id
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear l2tp tunnel allDaemonTear down every L2TP tunnel on this box.
clear l2tp tunnel all
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear l2tp tunnel idDaemonGracefully tear down one L2TP tunnel.
clear l2tp tunnel id
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear (other) 19
CommandModeDescriptionPipes
clear bgp healthcheckDaemonReset healthcheck probe to INIT
clear bgp healthcheck
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear bgp rib inDaemonRemove all routes received from a peer.
clear bgp rib in

Task supportforbidden: the MCP server never answers with a task handle

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear bgp rib outDaemonRe-advertise all routes to a peer.
clear bgp rib out

Task supportforbidden: the MCP server never answers with a task handle

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear debugOfflineClear the default debug profile.None
clear dns cacheDaemonFlush all DNS cache entries and reset all DNS cache counters.
clear dns cache

Subcommandsrecord stats

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear dns cache recordDaemonEvict DNS cache entries for one record name, or one name and type when a type is provided.
clear dns cache record <name> [type <A|AAAA|MX|NS|TXT|CNAME|PTR>]

Argumentsname string, required: yes, any value of this type: Record name to evict. The cache key, compared as an exact string. Alone, it evicts every type cached under the name and the answer counts the entries removed.
type enum, required: no, one of A AAAA MX NS TXT CNAME PTR: Optional DNS record type to evict for the named record. Written after the type keyword, it evicts that one type and leaves the other types of the name in place. The answer reports found true or false.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear dns cache statsDaemonReset DNS cache hit, miss, eviction, and expiry counters without removing cached entries.
clear dns cache stats
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear firewall domain-groupDaemonRemove the addresses Ze cached for a domain group.
clear firewall domain-group <name>

Argumentsname string, required: yes, any value of this type: Domain group name A group from the firewall configuration. The cache entries of that group's names are purged, and a name no group carries is an error.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear firewall irr as-setDaemonRemove the cached IRR prefix-list for an AS-SET.
clear firewall irr as-set <as-set>

Argumentsas-set string, required: yes, any value of this type: AS-SET name The RPSL set name the update command stored, for example AS-EXAMPLE. The entry under that exact name is purged.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear firewall irr asnDaemonRemove the cached IRR prefix-list for an ASN.
clear firewall irr asn <asn>

Argumentsasn string, required: yes, any value of this type: ASN number The AS number, 1 to 4294967294, in plain or dotted form. The entry purged is the one the update command stored under the decimal spelling.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear interface countersDaemonZero the Rx/Tx counters for every managed interface.
clear interface counters
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear interface name countersDaemonZero the Rx/Tx counters for one interface.
clear interface name <name> counters

Argumentsname string, required: yes, any value of this type: Interface name The interface whose counters are reset. The answer names it as the scope cleared, where the form without a name reports all.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear isis adjacencyDaemonTear down every IS-IS adjacency so neighbors re-form.
clear isis adjacency
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear isis countersDaemonReset IS-IS observational counters and the SPF log.
clear isis counters
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear ospf countersDaemonReset the OSPF SPF-run history.
clear ospf counters
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear ospf neighborDaemonTear down every OSPF adjacency so neighbors re-form.
clear ospf neighbor
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear ospf processDaemonFull OSPF reset: tear down every adjacency and re-run SPF.
clear ospf process
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear vpn ipsec saDaemonTear down IKE Security Associations.
clear vpn ipsec sa
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

clear vrrp statisticsDaemonReset every VRRP virtual router's counters to zero.
clear vrrp statistics
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

create 10
CommandModeDescriptionPipes
create bgp peerDaemonAdd a peer to the running daemon.
create bgp peer <selector> <asn> [local-as <local-as>] [local-address <local-address>] [router-id <router-id>] [receive-hold-time <receive-hold-time>] [send-hold-time <send-hold-time>] [connect-retry <connect-retry>] [connect <true|false>] [accept <true|false>] [family <family>] [graceful-restart <graceful-restart>] [group-updates <true|false>] [attach <attach>]

Argumentsselector union, required: yes, any value of this type: Address of the peer to create The token typed after 'peer' is an IPv4 or IPv6 address and nothing else. A name, a glob or an AS pattern is refused, because a peer that does not exist yet matches none of them. An address that already names a peer is refused.
asn union, required: yes, any value of this type: Remote AS of the peer, in any notation RFC 5396 names The value is 1 to 4294967295, in asplain or asdot notation. Ze stores the decimal form whichever notation you typed. AS 0 is refused, because RFC 7607 reserves it.
local-as union, required: no, any value of this type: Local AS for this session, overriding the router's, in any notation RFC 5396 names The value is 1 to 4294967295, in asplain or asdot notation. Absent, the session uses the router's own AS. AS 0 is refused.
local-address union, required: no, any value of this type: Local address to bind the session to The value is an IPv4 or IPv6 address of this router. Ze binds the TCP session to it. Absent, the kernel picks the source address.
router-id string, required: no, any value of this type: BGP Identifier for this session, overriding the router's The value is a dotted quad and it MUST NOT be 0.0.0.0. Ze sends it as the BGP Identifier in the OPEN for this session. Absent, the session uses the router's own.
receive-hold-time uint, required: no, any value of this type: Hold time in seconds (RFC 4271) The value is 0 to 65535 seconds and Ze puts it in the Hold Time field of its OPEN. The two peers then hold the lower of the two proposals. Absent, the value is 90.
send-hold-time uint, required: no, any value of this type: Send hold time in seconds, 0 for automatic (RFC 9687) The value is 0 to 65535 seconds. A non-zero value MUST be at least 480 and more than the receive hold time, or the peer is refused. 0 derives it as the larger of 480 and twice the receive hold time.
connect-retry uint, required: no, any value of this type: ConnectRetry interval in seconds The value is 0 to 65535 seconds and Ze reads it for a dynamic peer alone. A disconnected dynamic peer is removed after this delay when no connection comes back. A static peer reconnects on its own backoff, which this value does not change. Absent, the value is 120.
connect enum, required: no, one of true false: Dial the peer, default true The value is true or false and nothing else. With false, the session comes up only when the peer opens the TCP connection and 'accept' lets it in.
accept enum, required: no, one of true false: Accept a connection from the peer, default true The value is true or false and nothing else. With false, the session comes up only when 'connect' lets Ze dial the peer.
family string, required: no, any value of this type: Address families to negotiate, comma separated Each name is an AFI/SAFI pair such as ipv4/unicast, and a name Ze does not know is refused. Ze negotiates each family in the OPEN. Absent, the session uses the configured default families.
graceful-restart uint, required: no, any value of this type: Graceful restart time in seconds (RFC 4724) The value is 0 to 4095 seconds. It is the Restart Time Ze advertises in the graceful restart capability of its OPEN. Absent, the session advertises none.
group-updates enum, required: no, one of true false: Group this peer's UPDATEs with other peers, default true The value is true or false and nothing else. Packing reduces the number of UPDATE messages from one per route to one per set of path attributes. Use false for a peer that requires one prefix per UPDATE.
attach string, required: no, any value of this type: Plugin processes bound to this peer, comma separated Each name is a plugin process the configuration declares. Ze binds the peer to each one with the whole surface: the process receives every message from this peer and can send every type toward it. An empty name is refused.

15 operators · 1 column order

Column orderpeer, remote-as, message

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

create interface addressDaemonAdd an IP address to an interface.
create interface address <name> <prefix>

Argumentsname string, required: yes, any value of this type: Interface name The interface that receives the address. This form creates no interface, so the name must be present in the kernel before the command runs.
prefix union, required: yes, any value of this type: Address in CIDR form An IPv4 or IPv6 address with its prefix length, for example 10.0.0.1/24. Ze passes the string to the netlink backend.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

create interface bridge nameDaemonCreate a Linux bridge for L2 forwarding.
create interface bridge name <name>

Argumentsname string, required: yes, any value of this type: Interface name The name of the bridge to create. A name that holds an interface of another type is refused, and the error names both types.

Backendsnetlink

Subcommandsaddress unit

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

create interface bridge name addressDaemonAdd an IP address to the bridge.
create interface bridge name <name> address <prefix>

Argumentsname string, required: yes, any value of this type: Interface name The bridge that receives the address. The dispatcher creates it first when it is absent.
prefix union, required: yes, any value of this type: Address in CIDR form An IPv4 or IPv6 address with its prefix length, for example 10.0.0.1/32. Ze passes the string to the netlink backend.

Backendsnetlink

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

create interface bridge name unitDaemonAdd a VLAN sub-interface to the bridge.
create interface bridge name <name> unit <vid>

Argumentsname string, required: yes, any value of this type: Parent interface name The bridge the unit hangs off. The dispatcher creates it first when it is absent.
vid uint, required: yes, any value of this type: VLAN ID The 802.1Q tag of the unit. The new device is named <name>.<vid>, and a tag outside 1 to 4094 is refused before the backend is called.

Backendsnetlink

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

create interface dummy nameDaemonCreate a dummy (loopback-style) interface.
create interface dummy name <name>

Argumentsname string, required: yes, any value of this type: Interface name The name of the dummy to create. A name that holds an interface of another type is refused, and the error names both types.

Backendsnetlink

Subcommandsaddress unit

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

create interface dummy name addressDaemonAdd an IP address to the dummy.
create interface dummy name <name> address <prefix>

Argumentsname string, required: yes, any value of this type: Interface name The dummy that receives the address. The dispatcher creates it first when it is absent.
prefix union, required: yes, any value of this type: Address in CIDR form An IPv4 or IPv6 address with its prefix length, for example 10.0.0.1/32. Ze passes the string to the netlink backend.

Backendsnetlink

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

create interface dummy name unitDaemonAdd a VLAN sub-interface to the dummy.
create interface dummy name <name> unit <vid>

Argumentsname string, required: yes, any value of this type: Parent interface name The dummy the unit hangs off. The dispatcher creates it first when it is absent.
vid uint, required: yes, any value of this type: VLAN ID The 802.1Q tag of the unit. The new device is named <name>.<vid>, and a tag outside 1 to 4094 is refused before the backend is called.

Backendsnetlink

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

create interface unitDaemonAdd a VLAN sub-interface (802.1Q tagged).
create interface unit <name> <vid>

Argumentsname string, required: yes, any value of this type: Parent interface name The parent interface. This form creates no interface, so the name must be present in the kernel before the command runs.
vid uint, required: yes, any value of this type: VLAN ID The 802.1Q tag of the unit. The new device is named <name>.<vid>, and a tag outside 1 to 4094 is refused before the backend is called.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

create interface veth nameDaemonCreate a veth pair (two linked virtual Ethernet interfaces).
create interface veth name <name> <peer>

Argumentsname string, required: yes, any value of this type: Interface name The name of the first end of the pair. A pair already present under that name is reported, and nothing changes.
peer string, required: yes, any value of this type: Peer interface name The name of the second end. Both ends appear in the kernel after the one command.

Backendsnetlink

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

debug 4
CommandModeDescriptionPipes
debug ip ospf inject opaqueDaemonInject a crafted IPv4 opaque LSA into the local LSDB (RFC 5250).
debug ip ospf inject opaque scope <link|area|as> id <opaque-id> [type <type>] [hex <body> ...] [tlv <type> <value-hex> ...] [withdraw]

Subcommandshex id scope tlv type withdraw

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

debug ipv6 ospf inject lsaDaemonInject a crafted OSPFv3 LSA into the local LSDB (RFC 5340).
debug ipv6 ospf inject lsa type <ls-type> id <link-state-id> [scope <link|area|as>] [hex <body> ...] [withdraw]

Subcommandshex id scope type withdraw

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

debug ospf inject disableDaemonDisable OSPF debug LSA injection.
debug ospf inject disable
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

debug ospf inject enableDaemonEnable OSPF debug LSA injection (shared across both address families).
debug ospf inject enable
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

delete 6
CommandModeDescriptionPipes
delete bgp peerDaemonRemove a peer from the running config.
delete bgp peer <selector>

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. Ze tears down and deletes each peer it matches.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

delete debug moduleOfflineDisable debug for a subsystem, or remove one of its flags/scopes.None
delete debug profile nameOfflineDelete a named debug profile.None
delete interface nameDaemonDelete an interface from the kernel.
delete interface name <name>

Argumentsname string, required: yes, any value of this type: Interface name The interface to delete. The unit and address forms below keep this interface and remove one unit or one address of it.

Subcommandsaddress unit

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

delete interface name addressDaemonRemove an IP address from an interface.
delete interface name <name> address <prefix>

Argumentsname string, required: yes, any value of this type: Interface name The interface that holds the address. Its other addresses stay.
prefix union, required: yes, any value of this type: Address in CIDR form An IPv4 or IPv6 address with its prefix length. Ze passes the string to the netlink backend, so it must match the string the add used.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

delete interface name unitDaemonRemove a VLAN sub-interface.
delete interface name <name> unit <vid>

Argumentsname string, required: yes, any value of this type: Parent interface name The parent interface. Ze joins it with the VLAN id into <name>.<vid> and deletes that device.
vid uint, required: yes, any value of this type: VLAN ID The 802.1Q tag of the unit to remove. A tag outside 1 to 4094 is refused before the backend is called.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

doctor 1
CommandModeDescriptionPipes
doctorOfflineCheck that this system is ready to run Ze.None
explain 1
CommandModeDescriptionPipes
explainOfflineExplain one diagnostic code Ze printed.None
generate 1
CommandModeDescriptionPipes
generate wireguard keypairOfflineGenerate a WireGuard keypair with the system wg binary.None
help 3
CommandModeDescriptionPipes
helpRead-onlyShow available commands at this level.
help
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

help aiOfflinePrint the agent reference this binary builds from its own registries.None
help commandOfflineList every command this binary carries with its summary.None
monitor 8
CommandModeDescriptionPipes
monitor bgpRead-onlyLive BGP peer dashboard that refreshes automatically.
monitor bgp

Task supportrequired: the MCP server always answers with a task handle

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

monitor eventRead-onlyStream live events as they happen.
monitor event

Task supportrequired: the MCP server always answers with a task handle

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

monitor interface rateRead-onlyStream per-second traffic rates for your interfaces.
monitor interface rate

Task supportrequired: the MCP server always answers with a task handle

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

monitor pingRead-onlyContinuous ping with live loss and RTT statistics.
monitor ping

Task supportrequired: the MCP server always answers with a task handle

17 operators · answer: tab · 1 address field

Answer shapetab

Address fieldstarget

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill · resolve · origin

While streaminglog

Local process onlysave

monitor tracerouteRead-onlyLive mtr-style traceroute that updates continuously.
monitor traceroute

Task supportrequired: the MCP server always answers with a task handle

17 operators · answer: tab · 1 address field

Answer shapetab

Address fieldsaddr

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill · resolve · origin

While streaminglog

Local process onlysave

monitor traffic statRead-onlyStart streaming traffic monitor (per-second snapshots).
monitor traffic stat [name <name>]

Argumentsname string, required: no, any value of this type: Interface name filter The name of one interface, matched exactly against the interface names in each snapshot. Every other interface is left out of the stream.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

monitor vpn ipsecRead-onlyWatch IPsec SA events as they happen.
monitor vpn ipsec

Task supportrequired: the MCP server always answers with a task handle

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

plugin 10
CommandModeDescriptionPipes
plugin ackRead-onlyChoose sync or async event delivery.
plugin ack
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

plugin command completeRead-onlyList the completion candidates for a partial plugin command.
plugin command complete <partial>

Argumentspartial string, required: yes, any value of this type: Partial command text The text typed so far. The candidates match it on a case-insensitive prefix over the plugin command names.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

plugin command helpRead-onlyShow one plugin command's summary, explanation, arguments, and source plugin.
plugin command help <name>

Argumentsname string, required: yes, any value of this type: Plugin command name The full command name, as plugin command list prints it. A name no plugin registered fails with unknown plugin command.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

plugin command listRead-onlyList every command a plugin registered, with its summary.
plugin command list
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

plugin encodingRead-onlyChoose json or text encoding for plugin events.
plugin encoding
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

plugin formatRead-onlyChoose how BGP message bytes appear in events.
plugin format
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

plugin helpRead-onlyList the subcommands the plugin verb accepts.
plugin help
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

plugin session byeRead-onlyTell the daemon this session is disconnecting.
plugin session bye
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

plugin session pingRead-onlyAnswer a health check with the daemon process id.
plugin session ping
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

plugin session readyRead-onlySignal that this plugin process finished its initialization.
plugin session ready
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp 19
CommandModeDescriptionPipes
request bgp adj-rib-in accept-routesDaemonInstall one pending route under the validation state given.
request bgp adj-rib-in accept-routes
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp adj-rib-in batch-validateDaemonApply up to 256 validation decisions in one call.
request bgp adj-rib-in batch-validate
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp adj-rib-in disable-validationDaemonRemove RPKI gating without changing independent route authorization.
request bgp adj-rib-in disable-validation
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp adj-rib-in enable-validationDaemonTurn the validation gate on, so each new route waits in the pending state.
request bgp adj-rib-in enable-validation
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp adj-rib-in reject-routesDaemonDiscard one pending route and do not install it.
request bgp adj-rib-in reject-routes
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp adj-rib-in replayDaemonReplay the stored routes of every other peer to one target peer.
request bgp adj-rib-in replay
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp adj-rib-in revalidateDaemonAnswer the installed routes of one prefix, so a validator can validate them again.
request bgp adj-rib-in revalidate
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp rib fastpathDaemonSwitch or report the zero-copy forward-handle fast path.
request bgp rib fastpath <enable|disable|status>

Argumentsaction enum, required: yes, one of enable disable status: enable, disable or status One of the three words. Any other word is refused by name.

Task supportforbidden: the MCP server never answers with a task handle

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp rib injectDaemonInject a synthetic route into the Adj-RIB-In.
request bgp rib inject

Task supportforbidden: the MCP server never answers with a task handle

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp rib mark-staleDaemonMark peer routes at stale level
request bgp rib mark-stale
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp rib purge-staleDaemonPurge stale routes for peer
request bgp rib purge-stale
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp rib release-routesDaemonRelease retained peer RIB
request bgp rib release-routes
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp rib retain-routesDaemonMark peer RIB for retention
request bgp rib retain-routes
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp rib withdrawDaemonWithdraw a route from the Adj-RIB-In.
request bgp rib withdraw

Task supportforbidden: the MCP server never answers with a task handle

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp rib withdraw-protocolDaemonWithdraw all routes for a peer under a protocol
request bgp rib withdraw-protocol
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp rib withdraw-routerDaemonWithdraw all routes for a router under a protocol
request bgp rib withdraw-router
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp rpki validateDaemonValidate a prefix against the ROA cache
request bgp rpki validate <prefix> <origin-asn>
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp watchdog announceDaemonAnnounce routes in watchdog group
request bgp watchdog announce
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request bgp watchdog withdrawDaemonWithdraw routes in watchdog group
request bgp watchdog withdraw
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request interface 5
CommandModeDescriptionPipes
request interface downDaemonShut down an interface.
request interface <name> down

Argumentsname string, required: yes, any value of this type: Interface name The interface that up, down, mtu and mac act on. Each of those commands inherits it, and migrate names its own interfaces instead.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request interface macDaemonSet the MAC address on an interface.
request interface <name> mac <address>

Argumentsname string, required: yes, any value of this type: Interface name The interface that up, down, mtu and mac act on. Each of those commands inherits it, and migrate names its own interfaces instead.
address string, required: yes, any value of this type: MAC address, as xx:xx:xx:xx:xx:xx Six hexadecimal byte pairs separated by colons, in either case. The kernel device takes this address in place of the one it has.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request interface migrateDaemonMove IP addresses between interfaces with minimal downtime.
request interface migrate from <source> to <destination> address <prefix> [create <dummy|veth|bridge>] [timeout <duration>]

Subcommandsaddress create from timeout to

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request interface mtuDaemonSet the MTU on an interface.
request interface <name> mtu <bytes>

Argumentsname string, required: yes, any value of this type: Interface name The interface that up, down, mtu and mac act on. Each of those commands inherits it, and migrate names its own interfaces instead.
bytes uint, required: yes, any value of this type: MTU in bytes The largest frame payload the interface accepts. A value outside 68 to 65535 is refused before the backend is called.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request interface upDaemonBring an interface up.
request interface <name> up

Argumentsname string, required: yes, any value of this type: Interface name The interface that up, down, mtu and mac act on. Each of those commands inherits it, and migrate names its own interfaces instead.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request peer 9
CommandModeDescriptionPipes
request peer borrDaemonStart an Enhanced Route Refresh cycle (RFC 7313).
request peer <selector> borr

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. 'pause' and 'resume' refuse a selector that matches more than one peer, and the other commands act on each peer it matches.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request peer clear softDaemonSoft-clear a peer without dropping the session.
request peer <selector> clear soft

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. 'pause' and 'resume' refuse a selector that matches more than one peer, and the other commands act on each peer it matches.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request peer eorrDaemonFinish an Enhanced Route Refresh cycle (RFC 7313).
request peer <selector> eorr

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. 'pause' and 'resume' refuse a selector that matches more than one peer, and the other commands act on each peer it matches.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request peer flushDaemonWait until all queued updates for a peer are sent.
request peer <selector> flush

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. 'pause' and 'resume' refuse a selector that matches more than one peer, and the other commands act on each peer it matches.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request peer pauseDaemonPause reading from a peer's TCP socket.
request peer <selector> pause

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. 'pause' and 'resume' refuse a selector that matches more than one peer, and the other commands act on each peer it matches.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request peer plugin session readyDaemonSignal that per-peer plugin setup is complete.
request peer <selector> plugin session ready

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. 'pause' and 'resume' refuse a selector that matches more than one peer, and the other commands act on each peer it matches.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request peer refreshDaemonAsk a peer to re-send all routes (RFC 2918).
request peer <selector> refresh

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. 'pause' and 'resume' refuse a selector that matches more than one peer, and the other commands act on each peer it matches.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request peer resumeDaemonResume reading from a previously paused peer.
request peer <selector> resume

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. 'pause' and 'resume' refuse a selector that matches more than one peer, and the other commands act on each peer it matches.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request peer teardownDaemonTear down a peer session.
request peer <selector> teardown <cease-subcode>

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. 'pause' and 'resume' refuse a selector that matches more than one peer, and the other commands act on each peer it matches.
cease-subcode uint, required: yes, any value of this type: BGP cease NOTIFICATION subcode The value is a whole number from 0 to 255, and a value outside that range is refused. Ze puts it in the Cease NOTIFICATION it sends before it closes the session.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request (other) 19
CommandModeDescriptionPipes
request as112 healthcheckDaemonSend one authoritative query and check the AS112 answer.
request as112 healthcheck [target <target>]

Argumentstarget string, required: no, any value of this type: Anycast service address to query. An IP address, queried on port 53. When it is absent the query goes to the on-box loopback of the configured address family: 127.0.0.1, or ::1 when address-family is ipv6-only.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request cache expireDaemonRemove a cached message immediately.
request cache expire <id>

Argumentsid string, required: yes, any value of this type: Cache entry ID, or a comma-separated list of IDs. One decimal cache entry ID, as show cache lists it, or several joined by commas. A comma-separated value runs the action once for each ID and reports a failure for each ID that is not in the cache. A value that is not a decimal number is refused as an invalid cache id.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request cache releaseDaemonAck without forwarding (cache consumer) or undo retain (API).
request cache release <id>

Argumentsid string, required: yes, any value of this type: Cache entry ID, or a comma-separated list of IDs. One decimal cache entry ID, as show cache lists it, or several joined by commas. A comma-separated value runs the action once for each ID and reports a failure for each ID that is not in the cache. A value that is not a decimal number is refused as an invalid cache id.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request cache retainDaemonPrevent eviction of a cached message.
request cache retain <id>

Argumentsid string, required: yes, any value of this type: Cache entry ID, or a comma-separated list of IDs. One decimal cache entry ID, as show cache lists it, or several joined by commas. A comma-separated value runs the action once for each ID and reports a failure for each ID that is not in the cache. A value that is not a decimal number is refused as an invalid cache id.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request commitDaemonGroup route changes into named atomic commits.
request commit
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request config archiveDaemonSave a snapshot of the current running configuration.
request config archive
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request data backupDaemonWrite a backup of the whole store to a file on the daemon's host.
request data backup <path> [spare <spare>] [force]

Argumentspath string, required: yes, any value of this type: Absolute artifact path Absolute path of the artifact. A relative path, a '..' element, a symlink, and every name the store owns in its folder are refused, each naming the rule it broke.
spare uint, required: no, any value of this type: Spare capacity percent (0-100) Spare capacity in percent that each key and data slot carries. An artifact is normally copied whole, so the default is 0.
force flag, required: no, any value of this type: Replace an existing file Replace an existing file at path. It never lifts a refusal of a name the store owns.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request data restoreDaemonRestore a config from a backup file on the daemon's host.
request data restore <path> [config] [name <name>] [client <client>]

Argumentspath string, required: yes, any value of this type: Absolute artifact path Absolute path of the artifact, checked before it is read by the same rules as a backup path.
config flag, required: no, any value of this type: Restore the config only Restore the artifact's config only. A full restore replaces the whole store and runs offline with ze data restore.
name string, required: no, any value of this type: Config name inside the artifact The config to take from an artifact that holds several. Without it, the artifact's only config, or the config named like this device, is taken.
client string, required: no, any value of this type: Managed client whose served config is restored The managed client whose served config (client-<name>.conf) the restore writes. The daemon MUST be a hub with a client entry of this name. Without it, the restore replaces this daemon's own config through the reload.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request haltDaemonDump goroutine stacks to stderr and terminate immediately.
request halt
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request l2tp outgoing-call remote calledDaemonPlace an LNS-side outgoing call (RFC 2661 S10.4).
request l2tp outgoing-call remote <remote> called <called>

Argumentsremote string, required: yes, any value of this type: Configured l2tp/remote dial-target name. The name of an l2tp/remote entry, which supplies the address and the shared secret Ze dials with. An unknown name, or an entry without outgoing-calls, is refused before any packet is sent.
called string, required: yes, any value of this type: Called Number for the OCRQ. The number the remote LAC dials, as free text. Ze copies it into the Called Number AVP of the OCRQ without validation, so its form is what the LAC accepts.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request log levelDaemonChange a subsystem's log level without restarting.
request log level <logger> <disabled|debug|info|warn|err>

Argumentslogger string, required: yes, any value of this type: Logger/subsystem name The name of a registered logger, as 'show log levels' lists it. A name no logger registered is refused.
target enum, required: yes, one of disabled debug info warn err: Target log level The level the logger writes at from now on. The value is matched without regard to case, and 'error' and 'warning' are accepted as spellings of err and warn.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request mrt dump-ribDaemonWrite the current RIB to the MRT table dump file.
request mrt dump-rib
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request ospf graceful-restartDaemonTrigger a planned OSPFv2 graceful restart (RFC 3623 section 2.1).
request ospf graceful-restart
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request quiesceDaemonBlock until every subsystem has drained pending async work, then reply.
request quiesce
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request rebootDaemonGracefully shutdown then reboot the system.
request reboot
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request reloadDaemonReload the configuration without restarting.
request reload
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request shutdownDaemonGracefully shutdown: drain connections, close peers, exit.
request shutdown
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request subscribeDaemonStart receiving events of one or more types.
request subscribe

Task supportrequired: the MCP server always answers with a task handle

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

request unsubscribeDaemonStop receiving events you previously subscribed to.
request unsubscribe
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

resolve 11
CommandModeDescriptionPipes
resolve cymru asn-nameRead-onlyFind out who owns an AS number.
resolve cymru asn-name <asn>

Argumentsasn union, required: yes, any value of this type: AS number. The AS number in plain decimal or in asdot notation, which Ze parses to one 32-bit value before the query. A spelling that parses to no AS number is refused.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

resolve dns aRead-onlyLook up IPv4 addresses (A records) for a hostname.
resolve dns a <hostname>

Argumentshostname string, required: yes, any value of this type: Hostname to look up. A DNS name of 1 to 253 characters, which the router's own resolver queries. The first word after the command is the name, and a call with no name is refused with a usage line.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

resolve dns aaaaRead-onlyLook up IPv6 addresses (AAAA records) for a hostname.
resolve dns aaaa <hostname>

Argumentshostname string, required: yes, any value of this type: Hostname to look up. A DNS name of 1 to 253 characters, which the router's own resolver queries. The first word after the command is the name, and a call with no name is refused with a usage line.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

resolve dns ptrRead-onlyReverse-lookup an IP address to its hostname (PTR).
resolve dns ptr <ip-address>

Argumentsip-address string, required: yes, any value of this type: IP address to reverse-look-up. An IPv4 or IPv6 address in its usual text form. The resolver turns it into the reverse name itself, so pass the address and not the in-addr.arpa name.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

resolve dns txtRead-onlyLook up TXT records for a hostname.
resolve dns txt <hostname>

Argumentshostname string, required: yes, any value of this type: Hostname to look up. A DNS name of 1 to 253 characters, which the router's own resolver queries. The first word after the command is the name, and a call with no name is refused with a usage line.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

resolve irr expandRead-onlyExpand an AS-SET into its member AS numbers.
resolve irr expand
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

resolve irr prefixRead-onlyGet all prefixes announced by an AS-SET's members.
resolve irr prefix
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

resolve peeringdb as-setRead-onlyFind the IRR AS-SET registered for an ASN in PeeringDB.
resolve peeringdb as-set <asn>

Argumentsasn union, required: yes, any value of this type: AS number. The AS number in plain decimal or in asdot notation, which Ze parses to one 32-bit value before the query. A spelling that parses to no AS number is refused.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

resolve peeringdb max-prefixRead-onlyGet max-prefix limits for an ASN from PeeringDB.
resolve peeringdb max-prefix <asn>

Argumentsasn union, required: yes, any value of this type: AS number. The AS number in plain decimal or in asdot notation, which Ze parses to one 32-bit value before the query. A spelling that parses to no AS number is refused.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

resolve pingRead-onlyPing from the router with optional source binding.
resolve ping <target> [source <source>] [count <count>] [size <size>] [do-not-fragment <honor-cache|bypass-cache>]

Argumentstarget string, required: yes, any value of this type: Host or IP address to ping. The value follows the target keyword. A host name is resolved in either address family, and the family of the answer selects ICMPv4 or ICMPv6.
source string, required: no, any value of this type: Source IP address to bind. The value is a local IPv4 or IPv6 address, with an optional %zone, that Ze binds the echo socket to. Absent, the kernel picks the source.
count uint, required: no, any value of this type: Number of echo requests. Ze sends this many echo requests and waits 5 seconds for each reply. Absent, the value is 4.
size uint, required: no, any value of this type: ICMP echo payload size in bytes. Ze fills the payload to exactly this many bytes, with its marker copied into the front. Absent, Ze sends the small default payload.
do-not-fragment enum, required: no, one of honor-cache bypass-cache: Set the Don't Fragment bit; honor-cache obeys the cached path MTU, bypass-cache ignores it. The keyword takes one of two values. honor-cache sets the Don't Fragment bit and honors the kernel's cached path MTU: a probe larger than the cached value is refused at send time, and a router's Fragmentation Needed answer updates the cache. bypass-cache sets the bit and ignores the cached value, so the probe is put on the wire at its full size. Absent, the kernel fragments a probe larger than the path, which is the behavior of before the keyword existed.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

resolve tracerouteRead-onlyTraceroute from the router with optional source binding.
resolve traceroute <target> [source <source>] [max-hops <max-hops>] [timeout <timeout>] [probes <probes>] [do-not-fragment <honor-cache|bypass-cache>]

Argumentstarget string, required: yes, any value of this type: Host or IP address to trace to. The value follows the target keyword. A host name is resolved in the family of the source, or in either family when no source is given, and a name with no address in that family is refused.
source string, required: no, any value of this type: Source IP address to bind, whose family also selects the family the target is resolved in. The value is a local IPv4 or IPv6 address, with an optional %zone, that Ze binds the probe socket to. Absent, the kernel picks the source.
max-hops uint, required: no, any value of this type: Largest time-to-live to probe. The trace stops early when the target answers. Absent, the value is 30.
timeout string, required: no, any value of this type: Per-probe timeout, 1s to 30s, in Go duration syntax. The value is the time Ze waits for one probe before it records a missing answer. Absent, the value is 3s.
probes uint, required: no, any value of this type: Number of probes per hop. Each probe at one time-to-live reports its own round-trip time. Absent, the value is 3.
do-not-fragment enum, required: no, one of honor-cache bypass-cache: Set the Don't Fragment bit; honor-cache obeys the cached path MTU, bypass-cache ignores it. The keyword takes one of two values. honor-cache sets the Don't Fragment bit and honors the kernel's cached path MTU: a probe larger than the cached value is refused at send time, and a router's Fragmentation Needed answer updates the cache. bypass-cache sets the bit and ignores the cached value, so the probe is put on the wire at its full size. Absent, the kernel fragments a probe larger than the path, which is the behavior of before the keyword existed.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

send 9
CommandModeDescriptionPipes
send bgp blackholeDaemonOriginate a blackhole route on demand.
send bgp <selector> blackhole <prefix> [tag <key> <value>] [for <duration>]

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, a comma-separated list of those, or * for every peer. The message goes to each session the selector matches.
prefix string, required: yes, any value of this type: Prefix to blackhole, in CIDR form The value is an IPv4 or IPv6 prefix with its length, such as 192.0.2.1/32. The address family of the route follows from the prefix. A value that is not a prefix is refused.

Subcommandsfor tag

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

send bgp cachedDaemonSend a cached UPDATE to the peers the selector matches.
send bgp <selector> cached <id>

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, a comma-separated list of those, or * for every peer. The message goes to each session the selector matches.
id string, required: yes, any value of this type: Cache entry ID, or a comma-separated list of IDs. One decimal cache entry ID, as show cache lists it, or several joined by commas. A comma-separated value runs the action once for each ID and reports a failure for each ID that is not in the cache. A value that is not a decimal number is refused as an invalid cache id.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

send bgp flowspecDaemonOriginate a FlowSpec rule on demand (RFC 8955).
send bgp <selector> flowspec [destination-ipv4 <prefix> ...] [destination-ipv6 <prefix> ...] [destination-port <value> ...] [dscp <value> ...] [flow-label <value> ...] [fragment <value> ...] [icmp-code <value> ...] [icmp-type <value> ...] [next-header <value> ...] [packet-length <value> ...] [port <value> ...] [protocol <value> ...] [rd <value>] [source-ipv4 <prefix> ...] [source-ipv6 <prefix> ...] [source-port <value> ...] [tcp-flags <value> ...] [traffic-class <value> ...] (community <value>|rate-limit <bytes-per-second>|discard) [tag <key> <value>] [for <duration>]

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, a comma-separated list of those, or * for every peer. The message goes to each session the selector matches.

Subcommandsaction destination-ipv4 destination-ipv6 destination-port dscp flow-label for fragment icmp-code icmp-type next-header packet-length port protocol rd source-ipv4 source-ipv6 source-port tag tcp-flags traffic-class

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

send bgp rawDaemonSend raw bytes into a peer's TCP stream (dangerous).
send bgp <selector> raw <hex|b64> <data> [type <open|update|notification|keepalive|route-refresh>]

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, a comma-separated list of those, or * for every peer. The message goes to each session the selector matches.
encoding enum, required: yes, one of hex b64: How the data below is encoded. The word is required and it is typed before the data. Ze decodes the data with it, and data the decoder refuses is an error.
data string, required: yes, any value of this type: The bytes to send, in the encoding above. The value is one token, the octets in the encoding named before it. With a type keyword after it, the octets are the message body alone. Without one, they are the whole packet, marker and header included.
type enum, required: no, one of open update notification keepalive route-refresh: The BGP message type ze writes a header for. The word is optional and any other word there is refused. With it, Ze writes the 16-byte marker and the length and type fields, and the data is the body. Absent, the data is sent as it is.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

send bgp unicastDaemonOriginate a unicast route on demand.
send bgp <selector> unicast <prefix> [next-hop <address>] [community <value> ...] [tag <key> <value>] [for <duration>]

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, a comma-separated list of those, or * for every peer. The message goes to each session the selector matches.
prefix string, required: yes, any value of this type: Prefix to originate, in CIDR form The value is an IPv4 or IPv6 prefix with its length, such as 192.0.2.0/24. The address family of the route follows from the prefix. A value that is not a prefix is refused.

Subcommandscommunity for next-hop tag

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

send bgp updateDaemonSend a pre-built BGP UPDATE to a peer.
send bgp <selector> update <text|hex|b64|cursor>

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, a comma-separated list of those, or * for every peer. The message goes to each session the selector matches.
encoding enum, required: yes, one of text hex b64 cursor: How the tokens after this word are read. The word is required and any other word there is refused before the handler runs. hex and b64 keep the structure of text with the octets in place of the words. cursor keeps the attributes of the last command per process and peer, so a later command names only what changed, and 'cursor done' clears them.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

send bgp withdraw allDaemonWithdraw every on-demand announcement.
send bgp <selector> withdraw all

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, a comma-separated list of those, or * for every peer. The message goes to each session the selector matches.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

send bgp withdraw idDaemonWithdraw one announcement by the id that show announcements reports.
send bgp <selector> withdraw id <id>

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, a comma-separated list of those, or * for every peer. The message goes to each session the selector matches.
id string, required: yes, any value of this type: Announcement id, as show announcements reports it The value is the whole number show announcements reports in its id column. A value that is not a number is refused, and an id that names no announcement of the selector answers 'not found'.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

send bgp withdraw tagDaemonWithdraw the announcements carrying a tag.
send bgp <selector> withdraw tag <key> [value <value>]

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, a comma-separated list of those, or * for every peer. The message goes to each session the selector matches.
key string, required: yes, any value of this type: Tag key, or * for every tagged announcement The value is the key an announcement was made with, compared as text. Ze withdraws each announcement made to the selector that carries it. A key of * withdraws every tagged announcement made to the selector.
value string, required: no, any value of this type: Tag value, or every value of the key when absent The value is the tag value an announcement was made with, compared as text. With it, Ze withdraws the announcements under the key that carry this value alone. Absent, or *, every value of the key is withdrawn.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

set 6
CommandModeDescriptionPipes
set debug active nameOfflineLoad a named debug profile and apply it to the running daemon.None
set debug moduleOfflineEnable debug output for one subsystem.None
set debug profile nameOfflineSave the current debug state as a named profile.None
set debug timeoutOfflineSet how long debug output stays enabled.None
set sysctlDaemonSet a transient sysctl value
set sysctl <key> <value>
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

set system file-descriptorsDaemonRaise the file descriptor limit for the daemon process.
set system file-descriptors [limit <limit|max>]

Argumentslimit union, required: no, one of max: New limit or max for hard limit. The value is the new soft limit on open descriptors, a count from 1 up to the hard limit, or the word max. Ze sets it with setrlimit and reports the previous, the current and the hard limit. Zero, or a count above the hard limit, is refused.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show bfd 4
CommandModeDescriptionPipes
show bfd profileRead-onlyShow BFD timer profiles with effective values.
show bfd profile

Subcommandsname

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show bfd profile nameRead-onlyShow one BFD profile by name.
show bfd profile name <name>

Argumentsname string, required: yes, any value of this type: Profile name The name a bfd profile block declares in the configuration. The match is exact, and the values answered are the ones in effect after inheritance.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show bfd session addressRead-onlyShow full detail for one BFD session.
show bfd session address <address>

Argumentsaddress string, required: yes, any value of this type: Peer address An IPv4 or IPv6 address in its usual text form. A value that does not parse fails with bfd: invalid peer address before any lookup.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show bfd sessionsRead-onlyList all active BFD sessions.
show bfd sessions
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show bgp 37
CommandModeDescriptionPipes
show bgpRead-onlyBGP peers, sessions, RIB, and protocol tools.
show bgp

Subcommandsdecode encode health irr peer reject-asn rib update-delay

2 aliases · 17 operators · answer: tab · 1 address field · 2 column orders

Answer shapetab

Address fieldsaddress

Column orderaddress, name, description, remote-as, peer-type, state, uptime, state-changed, last-error, routes-received, routes-accepted, routes-sent, updates-received, updates-sent, keepalives-received, keepalives-sent, eor-received, eor-sent, connections-dropped; router-id, local-as, uptime, peers-configured, peers-established, family, peers-in-family, peers

Aliases
peers
The peer rows, without the aggregate fields display peers
summary
The aggregate fields, without the peer rows display router-id local-as uptime peers-configured peers-established

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill · resolve · origin

While streaminglog

Local process onlysave

show bgp adj-rib-inRead-onlyShow the routes held for each peer, with the wire bytes and validation state of each.
show bgp adj-rib-in
14 operators · answer: map

Answer shapemap

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display

While streaminglog

Local process onlysave

show bgp adj-rib-in statusRead-onlyShow whether the Adj-RIB-In runs, its total route count, and the count for each peer.
show bgp adj-rib-in status
9 operators · answer: doc

Answer shapedoc

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

show bgp decodeRead-onlyDecode a hex-encoded BGP message into readable JSON.
show bgp decode
None
show bgp encodeRead-onlyTurn a route announcement into wire-format hex.
show bgp encode
None
show bgp healthRead-onlyQuick health check for all your BGP peers.
show bgp health
17 operators · answer: tab · 1 address field · 1 column order

Answer shapetab

Address fieldspeer

Column orderpeer, state, as, uptime

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill · resolve · origin

While streaminglog

Local process onlysave

show bgp healthcheckRead-onlyShow healthcheck probe status
show bgp healthcheck
14 operators · answer: map

Answer shapemap

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display

While streaminglog

Local process onlysave

show bgp irrRead-onlyShow IRR filter status per ASN.
show bgp irr

Subcommandscheck prefix

15 operators · answer: tab · 2 column orders

Answer shapetab

Column orderasn, as-set, status, error, ipv4-count, ipv6-count, last-refresh, peers; server, last-refresh, next-refresh, entries

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show bgp irr checkRead-onlyCheck if a prefix is accepted by the IRR filter.
show bgp irr check <peer> <prefix>

Argumentspeer string, required: yes, any value of this type: Peer address. The address of an IRR-filtered peer, spelled as the configuration spells it. The prefix is evaluated against the list of the ASN that peer is enrolled under. An address no enrolled ASN carries is refused.
prefix string, required: yes, any value of this type: Prefix to check (CIDR). An IPv4 or IPv6 prefix in CIDR form, which Ze parses before the check. The answer echoes it and reports accepted true or false, with the entry that matched when one did.

9 operators · answer: doc · 1 column order

Answer shapedoc

Column orderprefix, asn, accepted, matched-entry

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

show bgp irr prefixRead-onlyShow IRR-resolved prefixes for a peer.
show bgp irr prefix <peer>

Argumentspeer string, required: yes, any value of this type: Peer address. The address of an IRR-filtered peer, spelled as the configuration spells it. The plugin finds the ASN the peer is enrolled under and answers that ASN's prefix list. An address no enrolled ASN carries is refused.

14 operators · answer: map · 1 column order

Answer shapemap

Column orderasn, as-set, prefixes

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display

While streaminglog

Local process onlysave

show bgp peer capabilitiesRead-onlyShow what capabilities were negotiated with a peer.
show bgp peer <selector> capabilities

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. Every command under 'show bgp peer' reads the peers it matches, except 'list', which reads every peer.

17 operators · answer: tab · 1 address field · 1 column order

Answer shapetab

Address fieldspeer

Column orderpeer, state, negotiation-complete, negotiated

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill · resolve · origin

While streaminglog

Local process onlysave

show bgp peer detailRead-onlyShow full detail for one or more peers.
show bgp peer <selector> detail

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. Every command under 'show bgp peer' reads the peers it matches, except 'list', which reads every peer.

17 operators · answer: tab · 2 address fields · 1 column order

Answer shapetab

Address fieldslocal-ip · next-hop-address

Column ordername, group, remote-as, local-as, peer-type, router-id, state, uptime, last-notification, local-ip, next-hop, next-hop-address, timer, capabilities

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill · resolve · origin

While streaminglog

Local process onlysave

show bgp peer historyRead-onlyShow FSM state transitions for a peer over time.
show bgp peer <selector> history

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. Every command under 'show bgp peer' reads the peers it matches, except 'list', which reads every peer.

15 operators · answer: tab · 1 column order

Answer shapetab

Column ordertimestamp, from, to, reason

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show bgp peer listRead-onlyList your peers, one line each.
show bgp peer list
15 operators · answer: tab · 1 column order

Answer shapetab

Column ordername, group, remote-as, state, uptime

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show bgp peer ribRead-onlyShow RIB data scoped to one peer.
show bgp peer <selector> rib [sent|advertised|received|sent-received]

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. Every command under 'show bgp peer' reads the peers it matches, except 'list', which reads every peer.

Subcommandsscope

17 operators · answer: tab · 2 address fields · 1 column order

Answer shapetab

Address fieldspeer · next-hop

Column orderpeer, direction, family, prefix, next-hop, path-id, as-path, origin, local-pref, med, communities

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill · resolve · origin

While streaminglog

Local process onlysave

show bgp peer statisticsRead-onlyShow UPDATE throughput for your peers.
show bgp peer <selector> statistics

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. Every command under 'show bgp peer' reads the peers it matches, except 'list', which reads every peer.

17 operators · answer: tab · 1 address field · 1 column order

Answer shapetab

Address fieldsaddress

Column orderaddress, remote-as, state, uptime, updates-received, updates-sent, keepalives-received, keepalives-sent, eor-received, eor-sent, rate-updates-received, rate-updates-sent, rate-keepalives-received, rate-keepalives-sent

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill · resolve · origin

While streaminglog

Local process onlysave

show bgp reject-asnRead-onlyShow every reject-asn list.
show bgp reject-asn

Subcommandsknown name

2 aliases · 15 operators · answer: tab · 2 column orders

Answer shapetab

Column ordername, import-peers, export-peers, entries, patterns; asn, positions, network

Aliases
peers
The peer rows, without the aggregate fields display peers
summary
The aggregate fields, without the peer rows display router-id local-as uptime peers-configured peers-established

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show bgp reject-asn known transit-freeRead-onlyPrint the curated transit-free ASNs as a config block.
show bgp reject-asn known transit-free
2 aliases · 9 operators · answer: doc · 2 column orders

Answer shapedoc

Column ordercurated, sources, networks, block; asn, name, contested

Aliases
peers
The peer rows, without the aggregate fields display peers
summary
The aggregate fields, without the peer rows display router-id local-as uptime peers-configured peers-established

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

show bgp reject-asn nameRead-onlyShow one reject-asn list.
show bgp reject-asn name <name>

Argumentsname string, required: yes, any value of this type: Reject-ASN list name The name of one configured reject-asn list. A name no list carries is refused, and the answer names the missing list.

2 aliases · 9 operators · answer: doc · 2 column orders

Answer shapedoc

Column ordername, import-peers, export-peers, entries, patterns; asn, positions, network

Aliases
peers
The peer rows, without the aggregate fields display peers
summary
The aggregate fields, without the peer rows display router-id local-as uptime peers-configured peers-established

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

show bgp ribRead-onlyQuery routes in the BGP RIB.
show bgp rib

Task supportrequired: the MCP server always answers with a task handle

Subcommandsbest protocol rpf status

13 command pipes · 17 operators · answer: tab · 2 address fields · 1 column order

Answer shapetab

Address fieldspeer · next-hop

Column orderpeer, direction, family, prefix, next-hop, path-id, as-path, origin, local-pref, med, communities

Command pipes
advertisedcommunity <value>countfamily <value>first <value>graphhistogramlast <value>match <value>path <value>peer <value>prefix <value>received
Command pipe descriptions
advertised
Select advertised routes
community <value>
Filter by standard community
count
Count matching routes without serializing rows
family <value>
Filter by AFI/SAFI
first <value>
Take first N routes
graph
Render AS-path topology graph
histogram
Count routes by family and prefix length
last <value>
Take last N routes
match <value>
Cross-field structured match
path <value>
Filter by AS path
peer <value>
Filter by peer
prefix <value>
Filter by prefix
received
Select received routes

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill · resolve · origin

While streaminglog

Local process onlysave

show bgp rib bestRead-onlyShow the winning route for each prefix.
show bgp rib best

Subcommandsstatus

12 command pipes · 17 operators · answer: tab · 2 address fields · 1 column order

Answer shapetab

Address fieldsbest-peer · next-hop

Column orderfamily, prefix, best-peer, multipath-peers, attributes

Command pipes
community <value>countfamily <value>first <value>graphhistogramlast <value>match <value>path <value>peer <value>prefix <value>reason
Command pipe descriptions
community <value>
Filter by standard community
count
Count matching best paths without serializing rows
family <value>
Filter by AFI/SAFI
first <value>
Take first N best paths
graph
Render AS-path topology graph
histogram
Count routes by family and prefix length
last <value>
Take last N best paths
match <value>
Cross-field structured match
path <value>
Filter by AS path
peer <value>
Filter by peer
prefix <value>
Filter by prefix
reason
Explain best-path selection

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill · resolve · origin

While streaminglog

Local process onlysave

show bgp rib best statusRead-onlyCheck whether best-path computation is still running.
show bgp rib best status
9 operators · answer: doc · 1 column order

Answer shapedoc

Column orderrunning, peers-with-rib, total-routes

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

show bgp rib commandsRead-onlyList RIB commands
show bgp rib commands
15 operators · answer: tab · 1 column order

Answer shapetab

Column ordername, description

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show bgp rib eventsRead-onlyList RIB event types
show bgp rib events
14 operators · answer: map

Answer shapemap

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display

While streaminglog

Local process onlysave

show bgp rib helpRead-onlyShow RIB subcommands
show bgp rib help
14 operators · answer: map

Answer shapemap

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display

While streaminglog

Local process onlysave

show bgp rib protocolRead-onlyQuery the routes one protocol feeds into the RIB.
show bgp rib protocol <protocol>

Argumentsprotocol string, required: yes, any value of this type: Registered protocol name The name of a registered protocol. The bgp-rib plugin refuses a name the protocol registry does not hold and names the registered ones.

13 command pipes · 17 operators · answer: tab · 2 address fields · 1 column order

Answer shapetab

Address fieldspeer · next-hop

Column orderpeer, direction, family, prefix, next-hop, path-id, as-path, origin, local-pref, med, communities

Command pipes
advertisedcommunity <value>countfamily <value>first <value>graphhistogramlast <value>match <value>path <value>peer <value>prefix <value>received
Command pipe descriptions
advertised
Select advertised routes
community <value>
Filter by standard community
count
Count matching routes without serializing rows
family <value>
Filter by AFI/SAFI
first <value>
Take first N routes
graph
Render AS-path topology graph
histogram
Count routes by family and prefix length
last <value>
Take last N routes
match <value>
Cross-field structured match
path <value>
Filter by AS path
peer <value>
Filter by peer
prefix <value>
Filter by prefix
received
Select received routes

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill · resolve · origin

While streaminglog

Local process onlysave

show bgp rib rpfRead-onlyReverse-path forwarding lookup in the Loc-RIB.
show bgp rib rpf
9 operators · answer: doc · 2 address fields · 1 column order

Answer shapedoc

Address fieldssource · next-hop

Column ordersource, family, found, matched-prefix, next-hop, distance, metric

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

show bgp rib statusRead-onlyGet a quick RIB overview without dumping routes.
show bgp rib status
9 operators · answer: doc · 1 column order

Answer shapedoc

Column orderrunning, peers, routes-in, routes-out, stale-routes, route-counts, gr-state

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

show bgp rpkiRead-onlyShow RPKI validation counters with one row for each cache server
show bgp rpki
1 alias · 17 operators · answer: tab · 1 address field · 1 column order

Answer shapetab

Address fieldsaddress

Column orderaddress, port, state, synced, version

Aliases
summary
The validation counters, without the cache server rows display vrp-count validation-enabled sessions-total sessions-established sessions-synced aspa-enabled aspa-records

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill · resolve · origin

While streaminglog

Local process onlysave

show bgp rpki aspaRead-onlyShow ASPA cache or lookup providers for a customer AS
show bgp rpki aspa
15 operators · answer: tab · 1 column order

Answer shapetab

Column ordercustomer-asn, providers

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show bgp rpki cacheRead-onlyShow RTR cache server sessions with protocol details
show bgp rpki cache
17 operators · answer: tab · 1 address field · 1 column order

Answer shapetab

Address fieldsaddress

Column orderaddress, port, preference, state, synced, version, session-id, serial, refresh-interval, retry-interval, expire-interval

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill · resolve · origin

While streaminglog

Local process onlysave

show bgp rpki roaRead-onlyShow ROA table entries or lookup covering VRPs for a prefix
show bgp rpki roa
17 operators · answer: tab · 1 address field · 1 column order

Answer shapetab

Address fieldsprefix

Column orderprefix, max-length, asn

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill · resolve · origin

While streaminglog

Local process onlysave

show bgp rpki statusRead-onlyShow RPKI validation status and cache server overview
show bgp rpki status
9 operators · answer: doc

Answer shapedoc

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

show bgp rpki summaryRead-onlyShow RPKI validation summary with session and ASPA counts
show bgp rpki summary
9 operators · answer: doc

Answer shapedoc

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

show bgp rs peersRead-onlyShow peer states
show bgp rs peers
17 operators · answer: tab · 1 address field · 1 column order

Answer shapetab

Address fieldsaddress

Column orderaddress, remote, up

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill · resolve · origin

While streaminglog

Local process onlysave

show bgp rs statusRead-onlyShow RS status
show bgp rs status
9 operators · answer: doc

Answer shapedoc

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

show bgp update-delayRead-onlyShow the startup convergence hold and what it waits for.
show bgp update-delay
9 operators · answer: doc · 1 column order

Answer shapedoc

Column orderconfigured, holding, released, reason, expected-peers, peers-held, peers-converged, max-delay-seconds, establish-wait-seconds

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

show bmp 4
CommandModeDescriptionPipes
show bmp collectorsRead-onlyShow BMP collector connection status.
show bmp collectors
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show bmp peersRead-onlyShow BGP peers as seen through BMP monitoring.
show bmp peers
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show bmp ribRead-onlyShow routes received via BMP monitoring sessions.
show bmp rib
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show bmp sessionsRead-onlyShow active BMP receiver sessions.
show bmp sessions
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show config 7
CommandModeDescriptionPipes
show config catRead-onlyPrint the full text of a stored configuration snapshot.
show config cat <id>

Argumentsid string, required: yes, any value of this type: Stored configuration snapshot id. The value is a key that show config list prints. Ze reads that file from the configuration store and writes its bytes unchanged.

None
show config diffRead-onlyCompare two configuration versions side by side.
show config diff
9 operators · answer: doc

Answer shapedoc

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

show config dumpRead-onlyShow the fully resolved configuration tree.
show config dump
9 operators · answer: doc

Answer shapedoc

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

show config fmtRead-onlyPretty-print the configuration with consistent formatting.
show config fmt
None
show config graphOfflineShow how components and peers depend on each other, as JSON.None
show config historyRead-onlyList available configuration rollback points.
show config history
15 operators · answer: tab · 1 column order

Answer shapetab

Column orderrevision, timestamp, path, state

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show config listRead-onlyList all configuration files stored in the database.
show config list
15 operators · answer: tab · 1 column order

Answer shapetab

Column ordersource, path

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show ddos 4
CommandModeDescriptionPipes
show ddos flowspecRead-onlyShow the upstream FlowSpec and RTBH DDoS mitigation status.
show ddos flowspec
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ddos incidentsRead-onlyShow the recent DDoS incident ring (newest first).
show ddos incidents
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ddos localRead-onlyShow the on-host DDoS mitigation status.
show ddos local
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ddos statusRead-onlyShow the DDoS observation status.
show ddos status
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show dns 4
CommandModeDescriptionPipes
show dns cache listRead-onlyList all non-expired DNS cache entries, sorted by shortest TTL first.
show dns cache list
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show dns cache recordRead-onlyShow DNS cache entries for one record name.
show dns cache record <name>

Argumentsname string, required: yes, any value of this type: Record name to inspect. The cache key, compared as an exact string. Each entry reported under it carries the name, the type, the records and the seconds of TTL left.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show dns cache statsRead-onlyShow the DNS cache hit, miss, eviction, expiry, and hit-rate counters.
show dns cache stats
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show dns lookupRead-onlyLook up a DNS name from the router.
show dns lookup <hostname> [type <A|AAAA|MX|NS|TXT|CNAME|PTR>]

Argumentshostname string, required: yes, any value of this type: Hostname to resolve. A DNS name of at most 253 characters. The first word that is not the type keyword is taken as the name, and a call with no name is refused.
type enum, required: no, one of A AAAA MX NS TXT CNAME PTR: DNS record type. The record type to query, written after the type keyword. The default is A. Ze upper-cases the value, and a type outside this list is refused with the list of accepted ones.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show event 4
CommandModeDescriptionPipes
show event deliveryRead-onlyShow which peers feed which attached processes.
show event delivery
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show event listRead-onlyList every event type you can subscribe to.
show event list
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show event namespacesRead-onlyList all event namespaces and how many events each has logged.
show event namespaces
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show event recentRead-onlyShow recent events, newest first.
show event recent
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show firewall 5
CommandModeDescriptionPipes
show firewall domain-groupRead-onlyShow what each configured domain group's DNS names resolve to.
show firewall domain-group [name <name>]

Argumentsname string, required: no, any value of this type: Group name; omit to list every group A group from the firewall configuration. A name no group carries is an error that lists the groups present.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show firewall groupRead-onlyShow members of a firewall address/port group.
show firewall group

Backendsnft

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show firewall irrRead-onlyShow IRR filter status for all cached ASN/AS-SET entries.
show firewall irr

Subcommandsprefix

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show firewall irr prefixRead-onlyShow IRR-resolved prefixes for a cached entry.
show firewall irr prefix <name>

Argumentsname string, required: yes, any value of this type: ASN or AS-SET name The cache key, as the update command stored it: an ASN in the form AS64500, or an AS-SET name. A key with no cached data is an error.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show firewall rulesetRead-onlyShow the live firewall ruleset with per-term counters.
show firewall ruleset <name>

Argumentsname string, required: yes, any value of this type: Firewall table name The table name as the configuration spells it, without the ze prefix the backend adds. A name no applied table carries is an error that lists the tables applied.

Backendsnft

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show host 10
CommandModeDescriptionPipes
show hostRead-onlyHardware inventory for this box.
show host

Subcommandsall cpu dmi kernel memory nic platform storage thermal

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show host allRead-onlyShow the full hardware inventory in one shot.
show host all
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show host cpuRead-onlyShow what CPUs are in this box.
show host cpu
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show host dmiRead-onlyShow the box's identity from SMBIOS/DMI.
show host dmi
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show host kernelRead-onlyShow the running kernel version and boot parameters.
show host kernel
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show host memoryRead-onlyShow installed memory and ECC health.
show host memory
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show host nicRead-onlyShow physical NICs installed in this box.
show host nic
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show host platformRead-onlyShow platform capabilities and constraints.
show host platform
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show host storageRead-onlyShow storage devices attached to this box.
show host storage
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show host thermalRead-onlyShow temperature sensors and thermal throttle events.
show host thermal
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show interface 8
CommandModeDescriptionPipes
show interfaceRead-onlyShow network interfaces on this box.
show interface

Subcommandsbrief errors name rate scan type

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show interface briefRead-onlyOne-line summary per interface: name, state, IP, and MTU.
show interface brief
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show interface errorsRead-onlyShow interfaces that have errors or drops.
show interface errors
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show interface name countersRead-onlyShow counters for one interface.
show interface name <name> counters

Argumentsname string, required: yes, any value of this type: Interface name The interface whose statistics are read. The answer repeats this name beside the Rx and Tx values.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show interface name detailRead-onlyShow full detail for one interface.
show interface name <name> detail

Argumentsname string, required: yes, any value of this type: Interface name The interface whose record is shown. The backend looks it up by this name, and an unknown name answers the backend's error.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show interface rateRead-onlyShow per-second traffic rates on your interfaces.
show interface rate
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show interface scanRead-onlyDiscover and classify all OS interfaces.
show interface scan
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show interface typeRead-onlyShow only interfaces of a given type.
show interface type <type>

Argumentstype string, required: yes, any value of this type: Ze interface type to filter by The type name the backend reports for an interface, compared without regard to case. When no interface has it, the error lists the types present.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show isis 8
CommandModeDescriptionPipes
show isis databaseRead-onlyShow the IS-IS link-state database.
show isis database

Subcommandsdetail

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show isis database detailRead-onlyShow the IS-IS link-state database with TLV detail.
show isis database detail
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show isis hostnameRead-onlyShow the IS-IS dynamic-hostname mapping (RFC 5301).
show isis hostname
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show isis interfaceRead-onlyShow IS-IS-enabled circuits.
show isis interface
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show isis neighborRead-onlyShow IS-IS adjacencies.
show isis neighbor
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show isis routeRead-onlyShow IS-IS-computed routes.
show isis route

Subcommandsipv6

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show isis route ipv6Read-onlyShow IS-IS-computed IPv6 routes (RFC 5308).
show isis route ipv6
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show isis spf-logRead-onlyShow recent IS-IS SPF runs.
show isis spf-log
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp 18
CommandModeDescriptionPipes
show l2tpRead-onlyL2TP tunnel, session, and subscriber state.
show l2tp

Subcommandsconfig cqm echo health listeners observer reliable session sessions statistics tunnel tunnels

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp configRead-onlyShow the resolved L2TP configuration.
show l2tp config
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp cqmRead-onlyShow subscriber line quality (CQM latency buckets).
show l2tp cqm
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp echoRead-onlyShow LCP echo health for a subscriber session.
show l2tp echo
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp healthRead-onlyFind your worst L2TP sessions at a glance.
show l2tp health
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp listenersRead-onlyShow which UDP sockets are listening for L2TP.
show l2tp listeners
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp observerRead-onlyShow recent events for a session (debug aid).
show l2tp observer
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp poolRead-onlyShow the IPv4 and IPv6 subscriber address pools and what each has allocated.
show l2tp pool
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp reliableRead-onlyShow the reliable transport window for a tunnel.
show l2tp reliable
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp session historyRead-onlyShow state transitions for a session over time.
show l2tp session history
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp session idRead-onlyShow full detail for one L2TP session.
show l2tp session id <id>

Argumentsid string, required: yes, any value of this type: Local session ID. The decimal local session ID from the show l2tp session table. Zero is refused because RFC 2661 reserves it, and an unknown ID is refused with 'no session with local-sid'.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp session trafficRead-onlyShow traffic counters for a subscriber's PPP interface.
show l2tp session traffic
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp sessionsRead-onlyList all active L2TP sessions.
show l2tp sessions
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp shaperRead-onlyShow each shaped subscriber session with its download and upload rate.
show l2tp shaper
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp statisticsRead-onlyShow aggregate L2TP protocol counters.
show l2tp statistics
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp tunnel historyRead-onlyShow state transitions for a tunnel over time.
show l2tp tunnel history
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp tunnel idRead-onlyShow full detail for one L2TP tunnel.
show l2tp tunnel id <id>

Argumentsid string, required: yes, any value of this type: Local tunnel ID. The decimal local tunnel ID from the show l2tp tunnel table. Zero is refused because RFC 2661 reserves it, and an unknown ID is refused with 'no tunnel with local-tid'.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show l2tp tunnelsRead-onlyList all active L2TP tunnels.
show l2tp tunnels
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show metrics 4
CommandModeDescriptionPipes
show metrics listRead-onlyList all registered metric names (no values).
show metrics list
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show metrics nameRead-onlyShow one Prometheus metric by name.
show metrics name <name> [label <key> <value> ...]

Argumentsname string, required: yes, any value of this type: Prometheus metric name The value is the whole metric name, such as ze_bgp_connect_retry_counter, compared as text with the start of each sample line. A name that matches no sample answers an empty list.

Subcommandslabel

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show metrics poolRead-onlyShow attribute pool memory usage and dedup efficiency.
show metrics pool
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show metrics valuesRead-onlyDump all metrics in Prometheus text format.
show metrics values
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf 49
CommandModeDescriptionPipes
show ospfRead-onlyShow the OSPFv2 process summary (RFC 2328).
show ospf

Subcommandsborder-routers database graceful-restart instance interface ipv6 ldp-sync neighbor route segment-routing spf te-database virtual-links

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf border-routersRead-onlyShow routes to OSPF area-border and AS-boundary routers.
show ospf border-routers
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf databaseRead-onlyShow the OSPF link-state database.
show ospf database

Subcommandsasbr-summary external network nssa-external opaque-area opaque-as opaque-link router router-information summary

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf database asbr-summaryRead-onlyShow only ASBR-Summary-LSAs (Type 4).
show ospf database asbr-summary
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf database externalRead-onlyShow only AS-external-LSAs (Type 5).
show ospf database external
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf database networkRead-onlyShow only Network-LSAs (Type 2).
show ospf database network
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf database nssa-externalRead-onlyShow only NSSA-external-LSAs (Type 7, RFC 3101).
show ospf database nssa-external
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf database opaque-areaRead-onlyShow only area-scope opaque-LSAs (Type 10, RFC 5250).
show ospf database opaque-area

Subcommandsdetail

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf database opaque-area detailRead-onlyDecode each area-scope opaque LSA body (RFC 5250).
show ospf database opaque-area detail
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf database opaque-asRead-onlyShow only AS-scope opaque-LSAs (Type 11, RFC 5250).
show ospf database opaque-as

Subcommandsdetail

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf database opaque-as detailRead-onlyDecode each AS-scope opaque LSA body (RFC 5250).
show ospf database opaque-as detail
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf database routerRead-onlyShow only Router-LSAs (Type 1).
show ospf database router
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf database router-informationRead-onlyShow the Router Information LSAs (RFC 7770) for both address families.
show ospf database router-information
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf database summaryRead-onlyShow only Summary-LSAs (Type 3, inter-area network).
show ospf database summary
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf graceful-restartRead-onlyShow OSPFv2 (IPv4) Graceful Restart state (RFC 3623).
show ospf graceful-restart
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf instanceRead-onlyShow the configured OSPFv2 instances (RFC 6549 Multi-Instance).
show ospf instance
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf interfaceRead-onlyShow OSPF-enabled interfaces.
show ospf interface

Subcommandsdetail

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf interface detailRead-onlyShow the full per-interface state (spec-ospf-ext-14).
show ospf interface detail
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6Read-onlyShow the OSPFv3 (IPv6) address-family instances (RFC 5838).
show ospf ipv6

Subcommandsdatabase graceful-restart instance interface neighbor segment-routing spf

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 databaseRead-onlyShow the OSPFv3 (IPv6) link-state database with each native scope-aware LSA decoded (RFC 5340).
show ospf ipv6 database

Subcommandsdetail extended router router-information scope segment-routing

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 database detailRead-onlyDecode every OSPFv3 LSA body with its scope-aware header (RFC 5340 section A.4.2.1).
show ospf ipv6 database detail
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 database extendedRead-onlyShow the extended OSPFv3 LSAs (RFC 8362).
show ospf ipv6 database extended
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 database router detailRead-onlyDecode each OSPFv3 Router-LSA body.
show ospf ipv6 database router detail
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 database router-informationRead-onlyShow the OSPFv3 Router Information LSAs (RFC 7770).
show ospf ipv6 database router-information
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 database scope areaRead-onlyShow only area-scope (S2/S1 = 01) LSAs.
show ospf ipv6 database scope area
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 database scope asRead-onlyShow only AS-scope (S2/S1 = 10) LSAs.
show ospf ipv6 database scope as
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 database segment-routingRead-onlySummarise the OSPFv3 Segment Routing content (RFC 8666) carried in the RI and extended LSAs.
show ospf ipv6 database segment-routing
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 graceful-restartRead-onlyShow OSPFv3 (IPv6) Graceful Restart state (RFC 5187).
show ospf ipv6 graceful-restart
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 instanceRead-onlyEnumerate the active OSPFv3 address-family instances (RFC 5838 section 2).
show ospf ipv6 instance
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 interfaceRead-onlyShow OSPFv3 (IPv6-family) interfaces and their RFC 4552 IPsec status.
show ospf ipv6 interface

Subcommandsdetail

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 interface detailRead-onlyShow the full per-interface OSPFv3 state (spec-ospf-ext-14).
show ospf ipv6 interface detail
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 neighborRead-onlyShow the OSPFv3 (IPv6) neighbors.
show ospf ipv6 neighbor

Subcommandsdetail

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 neighbor detailRead-onlyShow the full per-neighbor OSPFv3 state (spec-ospf-ext-14).
show ospf ipv6 neighbor detail
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 segment-routingRead-onlyShow OSPFv3 (IPv6) Segment Routing state (RFC 8666).
show ospf ipv6 segment-routing
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 spfRead-onlyShow the OSPFv3 (IPv6) per-area SPF run history.
show ospf ipv6 spf

Subcommandsdetail

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ipv6 spf detailRead-onlyExplain why each OSPFv3 route won (spec-ospf-ext-14), AF/Instance-ID tagged.
show ospf ipv6 spf detail
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf ldp-syncRead-onlyShow OSPF LDP-IGP synchronization state (RFC 5443, RFC 6138).
show ospf ldp-sync
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf neighborRead-onlyShow OSPF neighbors.
show ospf neighbor

Subcommandsdetail

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf neighbor detailRead-onlyShow the full per-neighbor state (spec-ospf-ext-14).
show ospf neighbor detail
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf routeRead-onlyShow OSPF-computed routes.
show ospf route

Subcommandsfast-reroute

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf route fast-rerouteRead-onlyShow OSPF fast-reroute (LFA / TI-LFA) backups (RFC 5286).
show ospf route fast-reroute
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf segment-routingRead-onlyShow OSPFv2 (IPv4) Segment Routing state (RFC 8665).
show ospf segment-routing
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf spfRead-onlyShow recent OSPF SPF runs.
show ospf spf

Subcommandsdetail

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf spf detailRead-onlyExplain why each route won the SPF calculation (spec-ospf-ext-14).
show ospf spf detail
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ospf te-databaseRead-onlyShow the OSPF Traffic Engineering Database (RFC 3630 / RFC 5392).
show ospf te-database
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show pki 6
CommandModeDescriptionPipes
show pki certificate nameRead-onlyInspect a specific certificate in detail.
show pki certificate name <name>

Argumentsname string, required: yes, any value of this type: Certificate name The name of a CA or device certificate in the store. An unknown name is refused, and the refusal lists the names the store holds.

Subcommandsbundle fingerprint pem

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show pki certificate name bundle pemRead-onlyExport the certificate, its intermediates and its private key as one PEM stream.
show pki certificate name <name> bundle pem

Argumentsname string, required: yes, any value of this type: Certificate name The name of a device certificate in the store. A CA name and a device certificate with no private key are each refused.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show pki certificate name fingerprintRead-onlyShow the hash of the certificate, to verify its identity against the one another system reports.
show pki certificate name <name> fingerprint [sha256|sha384|sha512]

Argumentsname string, required: yes, any value of this type: Certificate name The name of a CA or device certificate in the store. The hash is taken over its DER bytes. An unknown name is refused, and the refusal lists the names the store holds.

Subcommandsalgorithm

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show pki certificate name pemRead-onlyExport the certificate, and any intermediate it carries, as PEM.
show pki certificate name <name> pem

Argumentsname string, required: yes, any value of this type: Certificate name The name of a CA or device certificate in the store. An unknown name is refused, and the refusal lists the names the store holds.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show pki certificatesRead-onlyList all loaded certificates with expiry dates.
show pki certificates
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show pki local-ca pemRead-onlyExport the root certificate of the local certificate authority as PEM.
show pki local-ca pem
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show policy 4
CommandModeDescriptionPipes
show policy chain peerRead-onlyShow the import/export filter chain applied to a peer.
show policy chain peer <selector> [import|export]

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, or * for every peer. The chain of each peer it matches is shown.

Subcommandsdirection

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show policy listRead-onlyList all available filter types and named instances.
show policy list
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show policy routesRead-onlyShow policy-based routing rules.
show policy routes
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show policy test peerRead-onlyTest what your policy does to a specific UPDATE.
show policy test peer <selector> <import|export> [filter <name>] update <hex> [source-asn4 <true|false>]

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, or an AS pattern such as as65001. It MUST match exactly one peer: no match, and a match of several peers, are each refused.
direction enum, required: yes, one of import export: Which half of the chain to test The word is required, and a call without it is refused. It picks which of the peer's two chains the UPDATE is fed through.

Subcommandsfilter source-asn4 update

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show pppoe 5
CommandModeDescriptionPipes
show pppoeRead-onlyPPPoE session and protocol state.
show pppoe

Subcommandsinterfaces session sessions statistics

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show pppoe interfacesRead-onlyShow which interfaces are accepting PPPoE sessions.
show pppoe interfaces
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show pppoe session idRead-onlyShow full detail for one PPPoE session.
show pppoe session id <id>

Argumentsid string, required: yes, any value of this type: PPPoE session ID. The decimal sid column of the show pppoe session table. Zero is refused because RFC 2516 reserves it, and an unknown id is refused with 'no session with sid'.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show pppoe sessionsRead-onlyList all active PPPoE sessions.
show pppoe sessions
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show pppoe statisticsRead-onlyShow PPPoE protocol message counters.
show pppoe statistics
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show rsvp-te 5
CommandModeDescriptionPipes
show rsvp-te fast-rerouteRead-onlyShow RSVP-TE Fast Reroute (RFC 4090) protection state.
show rsvp-te fast-reroute
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show rsvp-te interfaceRead-onlyShow RSVP-TE bandwidth allocation per interface.
show rsvp-te interface
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show rsvp-te lspRead-onlyShow RSVP-TE label-switched paths.
show rsvp-te lsp
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show rsvp-te sessionRead-onlyShow each signaling session with its LSP state, role, bandwidth and labels.
show rsvp-te session
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show rsvp-te tunnelRead-onlyShow configured RSVP-TE tunnels and their current state.
show rsvp-te tunnel
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show schema 5
CommandModeDescriptionPipes
show schema eventsRead-onlyList all notification types defined in YANG API modules.
show schema events
15 operators · answer: tab · 1 column order

Answer shapetab

Column ordermethod, module, description

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show schema handlersRead-onlyShow which handler serves each YANG module.
show schema handlers
15 operators · answer: tab · 1 column order

Answer shapetab

Column orderhandler, module

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show schema listRead-onlyList all YANG schemas loaded by the daemon.
show schema list
15 operators · answer: tab · 1 column order

Answer shapetab

Column ordermodule, namespace, wants-config, imports

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show schema methodsRead-onlyList all RPC methods defined in YANG API modules.
show schema methods
15 operators · answer: tab · 1 column order

Answer shapetab

Column ordermethod, module, description

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show schema protocolRead-onlyShow the wire protocol version and format details.
show schema protocol
9 operators · answer: doc

Answer shapedoc

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

show sysctl 5
CommandModeDescriptionPipes
show sysctlRead-onlyShow all active sysctl keys with source and persistence
show sysctl
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show sysctl keyRead-onlyShow detail for one sysctl key
show sysctl key <key>
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show sysctl keysRead-onlyList all known sysctl keys with descriptions
show sysctl keys
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show sysctl profileRead-onlyShow detail for one sysctl profile
show sysctl profile <name>
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show sysctl profilesRead-onlyList all registered sysctl profiles
show sysctl profiles
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show system 15
CommandModeDescriptionPipes
show system conntrackRead-onlyShow the kernel connection tracking table.
show system conntrack

Backendsnft

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show system cpuRead-onlyShow CPU utilization context for the daemon.
show system cpu
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show system dateRead-onlyShow the daemon's current wall-clock time and timezone.
show system date
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show system file-descriptorsRead-onlyShow how many file descriptors the daemon has open.
show system file-descriptors [mode <summary|detail>]

Argumentsmode enum, required: no, one of summary detail: Display mode. The word is optional and the default is summary. Detail keeps the totals and appends the descriptor rows, so the output grows with the number of open files.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show system goroutinesRead-onlyDump goroutine stacks for debugging hangs or deadlocks.
show system goroutines [mode <summary|blocked|full>]

Argumentsmode enum, required: no, one of summary blocked full: Display mode. The word is optional and the default is summary. The blocked list carries each waiting goroutine with its id, its state and its stack, after the same totals. A full dump is one text block of up to 16 MB, so keep it for a hang.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show system kernel-logRead-onlyShow kernel log messages (dmesg-style).
show system kernel-log [level <emerg|alert|crit|err|warning|notice|info|debug>] [count <count>]

Argumentslevel enum, required: no, one of emerg alert crit err warning notice info debug: Filter by syslog level. The word is the highest syslog level to show, and every more severe level is included with it. A digit from 0 to 7 is accepted in its place. Absent, or not a known level, nothing is filtered.
count uint, required: no, any value of this type: Maximum number of messages. The value is from 1 to 10000 and the default is 50. Ze reads the whole ring buffer, applies the level filter, then keeps the newest count messages. A value outside the range is ignored and the default applies.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show system memoryRead-onlyShow how much memory the daemon is using, from the OS's view.
show system memory
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show system ntpRead-onlyNTP clock synchronization status.
show system ntp

Subcommandspeers

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show system ntp peersRead-onlyShow NTP peers with offset, RTT, stratum, and reachability.
show system ntp peers
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show system platformRead-onlyShow what kind of platform the daemon is running on.
show system platform
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show system profileRead-onlyCapture a runtime profile for performance analysis.
show system profile [type <cpu|heap|goroutine|allocs>] [duration <duration>]

Argumentstype enum, required: no, one of cpu heap goroutine allocs: Profile type. The word is optional and the default is heap. Only cpu runs for a time and reads duration. The three others return at once. The response carries the pprof bytes as base64 in data, with format pprof-base64.
duration string, required: no, any value of this type: Profile duration. The value is a Go duration with a unit, from 1s to 60s, and the default is 10s. Only a cpu profile reads it. A second cpu profile is refused while one runs.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show system socketsRead-onlyShow open TCP and UDP sockets on this box.
show system sockets [protocol <tcp|udp>] [state <state>] [port <port>]

Argumentsprotocol enum, required: no, one of tcp udp: Filter by protocol. The word is optional. Absent, the list carries both protocols. Ze reads /proc/net/tcp and /proc/net/tcp6 for tcp, and the udp pair for udp.
state string, required: no, any value of this type: Filter by socket state. The value is a kernel state name such as established, listen or time_wait, in any letter case. Only sockets in that state are listed. A UDP socket has no state to match.
port uint, required: no, any value of this type: Filter by port number. The value is a port number from 1 to 65535. A socket is listed when its local port or its remote port equals it. A value outside that range is ignored and the list is not filtered.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show system subsystem listRead-onlyList every registered subsystem and whether it is running.
show system subsystem list
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show system updateRead-onlyCheck if a firmware update is available.
show system update

Subcommandshistory

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show system update historyRead-onlyShow recent firmware update activity.
show system update history
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show traffic 4
CommandModeDescriptionPipes
show traffic controlRead-onlyShow traffic control (QoS) configuration per interface.
show traffic control
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show traffic featureRead-onlyShow neutral per-source traffic feature signals.
show traffic feature [name <name>]

Argumentsname string, required: no, any value of this type: Source address filter A source IP address, compared as text against each entry's address. Only the entries with that exact address are listed.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show traffic statRead-onlyShow aggregated traffic snapshot (interface rates, top talkers, top ports, severity).
show traffic stat [name <name>]

Argumentsname string, required: no, any value of this type: Interface name filter The name of one interface, matched exactly against the interface names in the snapshot. A name in no row leaves the answer empty.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show traffic usageRead-onlyShow per-interface traffic byte counters captured by eBPF TCX.
show traffic usage [name <name>]

Argumentsname string, required: no, any value of this type: Interface name (used with 'name <interface>') The kernel interface name, as configured under traffic usage. An interface the plugin does not monitor fails with interface not monitored.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show vpn 6
CommandModeDescriptionPipes
show vpn ipsec dataplane driftRead-onlyCompare what the IKE engine believes against what the kernel holds.
show vpn ipsec dataplane drift
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show vpn ipsec dataplane policyRead-onlyShow the Security Policy Database the kernel holds.
show vpn ipsec dataplane policy
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show vpn ipsec dataplane saRead-onlyShow the Security Association Database the kernel holds.
show vpn ipsec dataplane sa [spi <spi>]

Argumentsspi uint, required: no, any value of this type: Show all SAs with this SPI. The value is decimal. Ze keeps only the SAs whose SPI equals it, and the inbound SA and the outbound SA of one tunnel carry different SPIs, so one value names one direction. The value 0 is refused.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show vpn ipsec peer nameRead-onlyShow full detail for one IPsec peer.
show vpn ipsec peer name <name>

Argumentsname string, required: yes, any value of this type: Configured IPsec peer name. The value is the key of a site-to-site peer entry, at most 255 characters. Ze returns every IKE SA that peer holds, and answers 'peer not found' when none is up.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show vpn ipsec saRead-onlyShow all IKE and Child Security Associations.
show vpn ipsec sa
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show vpn ipsec statusRead-onlyQuick IPsec health check.
show vpn ipsec status
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show vpp 4
CommandModeDescriptionPipes
show vpp runtimeRead-onlyShow VPP graph node processing statistics.
show vpp runtime
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show vpp trace clearRead-onlyDiscard the captured VPP trace buffer.
show vpp trace clear
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show vpp trace showRead-onlyRetrieve packets captured since the last trace start.
show vpp trace show
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show vpp trace startRead-onlyStart capturing packets in the VPP dataplane.
show vpp trace start
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show vrrp 4
CommandModeDescriptionPipes
show vrrpRead-onlyShow every VRRP virtual router.
show vrrp

Subcommandsinterface statistics

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show vrrp interfaceRead-onlyShow the VRRP virtual routers hosted on one interface.
show vrrp interface name <interface>

Subcommandsname

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show vrrp interface nameRead-onlyShow the VRRP virtual routers on one parent interface.
show vrrp interface name [value <value>]

Argumentsvalue string, required: no, any value of this type: Parent interface name The name of the parent interface whose virtual routers the answer lists. The word after the name keyword is the value, and a bare word with no keyword is accepted from a programmatic sender.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show vrrp statisticsRead-onlyShow per-virtual-router counters.
show vrrp statistics
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show (other) 70
CommandModeDescriptionPipes
show aaa accountingRead-onlyShow AAA accounting counters and any dropped records.
show aaa accounting
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show announcementsRead-onlyList active on-demand announcements.
show announcements [tag <tag>] [selector <selector>] [family <family>]

Argumentstag string, required: no, any value of this type: Show only announcements carrying this tag key The value is a tag key, compared as text with the key each announcement was made with. Absent, announcements of every key are listed.
selector string, required: no, any value of this type: Show only announcements whose peer selector matches this pattern The value is compared as text with the selector the announcement was made with, so it MUST be spelled the way that announcement spelled it. Absent, announcements to every selector are listed.
family string, required: no, any value of this type: Show only announcements of this address family The value is an address family as the family column reports it, such as ipv4/unicast. Absent, announcements of every family are listed.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show anomaly detectRead-onlyShow the recent behavioral anomaly incidents.
show anomaly detect
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show anomaly observeRead-onlyShow the behavioral anomaly incident lifecycle, newest first.
show anomaly observe
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show anomaly shapeRead-onlyShow the shadow-first anomaly responder status.
show anomaly shape
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show arpRead-onlyShow the IPv4 ARP table (shortcut for 'show neighbor ipv4').
show arp
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show as112Read-onlyAS112 node status.
show as112
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show auditRead-onlyShow who did what and when on this box.
show audit [action <action>] [actor <actor>] [surface <surface>] [since <since>] [until <until>] [count <count>]

Argumentsaction string, required: no, any value of this type: Filter by action type The value is an action name as the action column reports it, such as config-commit or login, compared as text. Absent, entries of every action are shown.
actor string, required: no, any value of this type: Filter by actor name The value is the name of the user or process that acted, compared as text with the actor column. Absent, entries of every actor are shown.
surface string, required: no, any value of this type: Filter by surface name The value is the surface the action came through: cli, web or api, compared as text. Absent, entries of every surface are shown.
since string, required: no, any value of this type: Start time (RFC3339) The value is an RFC 3339 timestamp such as 2026-09-15T08:00:00Z, and any other form is refused. Entries recorded before it are left out.
until string, required: no, any value of this type: End time (RFC3339) The value is an RFC 3339 timestamp such as 2026-09-15T18:00:00Z, and any other form is refused. Entries recorded after it are left out.
count uint, required: no, any value of this type: Maximum number of entries The value is a whole number of 1 or more. The query stops after that many matching entries, oldest first. Absent, every matching entry is shown.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show cacheRead-onlyList the cached BGP UPDATE message IDs.
show cache
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show captureRead-onlyShow captured control-plane messages.
show capture [protocol <l2tp|bgp>] [tunnel-id <tunnel-id>] [count <count>] [peer <peer>]

Argumentsprotocol enum, required: no, one of l2tp bgp: Protocol filter. Restricts the answer to one protocol key. Absent, the answer carries an l2tp key and a bgp key, each holding its messages or 'capture not enabled'.
tunnel-id string, required: no, any value of this type: L2TP tunnel ID filter. Keeps only the L2TP messages of the tunnel with this local tunnel ID. The BGP messages are not affected.
count uint, required: no, any value of this type: Maximum number of messages. At most this many messages are returned for each protocol. Absent or 0, every buffered message is returned.
peer string, required: no, any value of this type: Peer address filter. Keeps only the messages exchanged with this peer address, for L2TP and BGP alike.

Subcommandsinterface raw

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show capture interfaceRead-onlyCapture live packets on an interface (like tcpdump).
show capture interface [iface <iface>] [count <count>] [duration <duration>] [snap-len <snap-len>] [format <pcap|text>] [protocol <protocol>]

Argumentsiface string, required: no, any value of this type: Interface name. The interface name as the configuration spells it. Ze resolves it to the kernel device before it opens the socket. One capture at a time runs per interface, and a second call on the same name is refused.
count uint, required: no, any value of this type: Packet count. The capture ends when this many packets have been read or when the duration has elapsed, whichever comes first. The default is 100.
duration string, required: no, any value of this type: Capture duration. The time the socket stays open, from 1s to 60s. The default is 10s. The capture ends earlier when the packet count is reached.
snap-len uint, required: no, any value of this type: Snap length in bytes. The number of bytes kept from the start of each packet. The default is 65535, which keeps whole packets. The value is written into the pcap file header.
format enum, required: no, one of pcap text: Output format. The default is pcap. Both forms carry a packets count with the data.
protocol string, required: no, any value of this type: Protocol filter. A pcap-filter word such as tcp or udp. Ze joins it to every other word after the interface name and compiles the whole expression to a BPF program on the socket.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show capture rawRead-onlyControl raw byte capture for protocol debugging.
show capture raw [action <start|stop|dump>] [protocol <l2tp|bgp>] [format <pcap|json>] [count <count>]

Argumentsaction enum, required: no, one of start stop dump: Capture action. The verb the command performs. It is required, and a call without one is refused with the usage line.
protocol enum, required: no, one of l2tp bgp: Protocol to capture. Narrows the action to one protocol. Absent, the action applies to every protocol with a raw capture, and the answer carries one key for each.
format enum, required: no, one of pcap json: Output format. Read by dump alone. The default is json. With pcap the answer carries a <protocol>-pcap key holding the base64 file and a <protocol>-packets count.
count uint, required: no, any value of this type: Maximum number of messages. Read by dump alone. At most this many messages are returned for each protocol. Absent or 0, every captured message is returned.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show class-of-serviceRead-onlyShow each class-of-service profile with its ingress and egress marking maps.
show class-of-service
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show command completeRead-onlyGet tab-completion candidates for a partial command.
show command complete
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show command helpRead-onlyShow usage and arguments for a specific command.
show command help
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show command listRead-onlyList every command the daemon knows about.
show command list
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show crashesRead-onlyView saved crash reports, and whether kernel capture is armed.
show crashes [name <name>]

Argumentsname string, required: no, any value of this type: Crash report name (used with 'name <filename>'). The file name of one stored report, as the listing prints it. Ze reads that file from the crash directory and prints it. A name holding a slash or '..' is refused.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show data catRead-onlyPrint the value of a storage key.
show data cat <key>

Argumentskey string, required: yes, any value of this type: Storage key to print The key of one entry, as show data list prints it. The bytes stored under it are written out unchanged, and a key the store does not hold is an error.

None
show data listRead-onlyList the keys in the selected store.
show data list
15 operators · answer: tab · 1 column order

Answer shapetab

Column orderkey

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show data registeredRead-onlyList the key patterns registered by all subsystems.
show data registered
15 operators · answer: tab · 1 column order

Answer shapetab

Column orderpattern, description

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show debugRead-onlyShow live debug state from the running daemon.
show debug
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show debug profileOfflineShow stored debug profiles, one by name, or one filtered to a module subtree.None
show doctorRead-onlyCheck if this box is ready to run Ze.
show doctor
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ecmp-groupsRead-onlyShow each prefix the system RIB holds equal-cost paths for, whether or not Ze programs them.
show ecmp-groups
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show env getRead-onlyShow one environment variable in detail.
show env get <name>

Argumentsname string, required: yes, any value of this type: Environment variable name The variable's full name as Ze registered it, matched exactly. A name Ze never declared is refused, even when the process inherited it.

15 operators · answer: tab · 1 column order

Answer shapetab

Column orderkey, type, default, current, description

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show env listRead-onlyList all Ze environment variables with their current values.
show env list
15 operators · answer: tab · 1 column order

Answer shapetab

Column orderkey, type, default, current, description

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show env registeredRead-onlyList every registered environment variable with metadata.
show env registered
15 operators · answer: tab · 1 column order

Answer shapetab

Column orderkey, type, default, current, description

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show errorsRead-onlyShow recent errors across all subsystems, newest first.
show errors
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show fib kernelRead-onlyShow the routes this backend programmed into the Linux forwarding table.
show fib kernel
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show fib p4Read-onlyShow the routes this backend programmed into the P4 forwarding pipeline.
show fib p4
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show fib vppRead-onlyShow the routes this backend programmed into the VPP forwarding table.
show fib vpp
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show flow exportRead-onlyShow flow export (NetFlow/IPFIX) collector status.
show flow export [name <name>]

Argumentsname string, required: no, any value of this type: Collector name (used with 'name <name>'). The value is the key of a configured collector. Ze returns that one collector with its protocol counters and errors, and answers 'collector not found' for any other value.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show flow recentRead-onlyShow recent conntrack flow records from the bounded recent-flow ring.
show flow recent [dst <dst>]

Argumentsdst string, required: no, any value of this type: Destination prefix or address to filter by (used with 'dst <prefix>'). The value is an IPv4 or IPv6 prefix in CIDR form, or a bare address, which Ze reads as a /32 or a /128. Ze keeps only the ring records whose destination is inside that prefix.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show geodnsRead-onlyShow the GeoDNS server status.
show geodns
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show gnmiRead-onlyShow whether the gNMI server is running and how it is configured.
show gnmi
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show healthRead-onlyShow the health of every component and the overall status of this box.
show health
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ldp bindingRead-onlyShow LDP FEC-to-label bindings.
show ldp binding
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ldp neighborRead-onlyShow LDP neighbors and their session state.
show ldp neighbor
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show log levelsRead-onlyShow what log level each subsystem is using.
show log levels
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show log recentRead-onlyShow recent log entries from the in-memory ring.
show log recent [level <disabled|debug|info|warn|err>] [component <component>] [count <count>]

Argumentslevel enum, required: no, one of disabled debug info warn err: Filter by log level Keeps the entries whose level equals this value, and no other level. Without it every level is shown.
component string, required: no, any value of this type: Filter by component name Keeps the entries whose component name equals this value exactly. Without it every component is shown.
count uint, required: no, any value of this type: Maximum number of entries Stops the answer after this many entries, newest first. It MUST be 1 or more, and without it every buffered entry is shown.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show mpls forwardingRead-onlyShow MPLS forwarding entries installed in the kernel.
show mpls forwarding [limit <limit>]

Argumentslimit uint, required: no, any value of this type: Maximum number of entries. The value is a positive integer. Ze returns at most that many entries and sets truncated to true when the kernel holds more. Absent, the value is 100000.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show mtuRead-onlyMeasure the path MTU and size the IPsec tunnels from it.
show mtu [host <host>] [search <exhaustive>] [view <detail>]

Argumentshost union, required: no, any value of this type: Measure one address instead of the IPsec peers. The value follows the host keyword and is one IPv4 or IPv6 address. Ze measures the path MTU to that address alone and skips the peers and the reference address. A name is refused: the run sends probes to the address as typed.
search enum, required: no, one of exhaustive: exhaustive: a slower run that probes every size and discards the cached and reported path MTU. The bare word exhaustive makes the run slower and its figure comes from probing every size on the wire: the path MTU the kernel remembered and the value a router reported are both discarded, so a stale or poisoned cache value cannot reach the answer.
view enum, required: no, one of detail: detail: report every probe sent and every reply received. The bare word detail adds, per target, the size of every probe sent and the answer each one received, so an operator can follow how the value was found.

9 operators · answer: doc

Answer shapedoc

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

show neighborRead-onlyShow the ARP and neighbor discovery table.
show neighbor [family <ipv4|ipv6|any|all>]

Argumentsfamily enum, required: no, one of ipv4 ipv6 any all: Address family filter Selects the address family the answer carries. The default when it is absent is both families.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show nexthop-tableRead-onlyShow each next hop the resolver tracks and the direct next hop it resolves to.
show nexthop-table
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show pingRead-onlyPing a target from the router itself.
show ping [dest <dest>] [count <count>] [size <size>] [timeout <timeout>] [do-not-fragment <honor-cache|bypass-cache>]

Argumentsdest string, required: no, any value of this type: Target host or IP address. The value is the first bare word of the command. A host name is resolved in either address family, and the family of the answer selects ICMPv4 or ICMPv6.
count uint, required: no, any value of this type: Number of ping packets. The value is the number of echo requests Ze sends, 1 to 100, paced 10 milliseconds apart. Absent, the value is 5.
size uint, required: no, any value of this type: ICMP echo payload size in bytes (1-65507). Omit for the engine default. Ze fills the payload to exactly this many bytes, with its marker copied into the front so a capture still identifies the sender.
timeout string, required: no, any value of this type: Timeout duration. The value is the time Ze waits for each reply, in Go duration syntax, 1s to 30s. Absent, the value is 5s.
do-not-fragment enum, required: no, one of honor-cache bypass-cache: Set the Don't Fragment bit; honor-cache obeys the cached path MTU, bypass-cache ignores it. The keyword takes one of two values. honor-cache sets the Don't Fragment bit and honors the kernel's cached path MTU: a probe larger than the cached value is refused at send time, and a router's Fragmentation Needed answer updates the cache. bypass-cache sets the bit and ignores the cached value, so the probe is put on the wire at its full size. Absent, the kernel fragments a probe larger than the path, which is the behavior of before the keyword existed.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show plugin declarationsRead-onlyShow what each plugin declares about its command surface.
show plugin declarations

Subcommandsconfig

15 operators · answer: tab · 1 column order

Answer shapetab

Column ordername, kind, state, commands, pipes, reason

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show plugin declarations configRead-onlyRead the plugin blocks of a config file as well.
show plugin declarations config <path>

Argumentspath string, required: yes, any value of this type: Path of the config file whose plugin blocks are read One filesystem path, or - for a config arriving on stdin. A path that names no readable file is refused before the read, and a second path after it is refused.

15 operators · answer: tab · 1 column order

Answer shapetab

Column ordername, kind, state, commands, pipes, reason

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show plugin listRead-onlyList the plugins compiled into this binary.
show plugin list
15 operators · answer: tab · 1 column order

Answer shapetab

Column ordername, description, outcome, families, rfcs, capabilities, reason

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show probe-roundRead-onlyRun a parallel traceroute probe round to a target.
show probe-round [dest <dest>] [probes <probes>] [max-hops <max-hops>] [timeout <timeout>]

Argumentsdest string, required: no, any value of this type: Target host or IP address. The value is the first bare word of the command. A host name is resolved in either address family, and the family of the answer selects ICMPv4 or ICMPv6.
probes uint, required: no, any value of this type: Number of probes per hop. The value is accepted in the range 1 to 10 and then not read: a probe round sends one probe at each time-to-live.
max-hops uint, required: no, any value of this type: Maximum number of hops. The value is the largest time-to-live Ze probes, 1 to 64. Absent, or set to 30, the round probes 16 hops.
timeout string, required: no, any value of this type: Timeout duration. The value is accepted in Go duration syntax, 1s to 30s, and then not read: a probe round waits one second for every answer.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show reload-statusRead-onlyShow how many config reloads the daemon has processed.
show reload-status
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show resolve rirRead-onlyShow which Regional Internet Registry holds an AS number.
show resolve rir <asn>

Argumentsasn union, required: yes, any value of this type: AS number to look up. The AS number in plain decimal or in asdot notation, which Ze parses to one 32-bit value before it searches the delegation table.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show ribRead-onlyShow each route the system RIB holds, with its family, next hop, protocol and equal-cost paths.
show rib
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show routeRead-onlyShow the kernel routing table.
show route [prefix <prefix>] [limit <limit>]

Argumentsprefix string, required: no, any value of this type: CIDR prefix filter A prefix in CIDR form, or the word default. Only routes for that prefix are listed, and every route is listed when it is absent.
limit uint, required: no, any value of this type: Maximum number of routes The largest number of routes the answer carries, given after the word limit. The default is 100000, and the answer says when it was truncated.

Subcommandslookup

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show route lookupRead-onlyLook up which route the kernel would use for a given IP.
show route lookup <ip>

Argumentsip string, required: yes, any value of this type: Destination IP address to look up One IPv4 or IPv6 address without a prefix length. The kernel answers with the route it selects for a packet to that address.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show rr peersRead-onlyShow route reflector client peers.
show rr peers
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show rr statusRead-onlyShow whether the route reflector is active.
show rr status
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show runtime memoryRead-onlyShow the Go runtime allocator memory stats.
show runtime memory
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show staticRead-onlyShow static routes defined in the configuration.
show static
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show statusRead-onlyShow process status, uptime, and resource usage.
show status
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show storage smartRead-onlyShow disk health via SMART data.
show storage smart
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show subscriberRead-onlyShow a summary of all subscriber sessions.
show subscriber

Subcommandsid

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show subscriber id detailRead-onlyShow everything about one subscriber session.
show subscriber id <id> detail

Argumentsid string, required: yes, any value of this type: Subscriber session ID. The id column of the show subscriber table. An L2TP session is named l2tp-<tunnel-id>-<session-id> and a PPPoE session pppoe-<ifindex>-<session-id>. An unknown id is refused with 'session not found'.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show tcp-checkRead-onlyTest TCP connectivity to a remote host and port.
show tcp-check <host> <port> [source <source>] [timeout <timeout>]

Argumentshost string, required: yes, any value of this type: Target host. An IP address or a DNS name of at most 253 characters, which the dialer resolves. The answer echoes it in the host key.
port uint, required: yes, any value of this type: Target port. The TCP port to connect to, from 1 to 65535. Ze joins it to the host and dials that one endpoint.
source string, required: no, any value of this type: Source IP address. A local IP address the connection binds to before it dials. An address the host does not hold makes the dial fail. Absent, the kernel picks the source.
timeout string, required: no, any value of this type: Connection timeout. How long the dial waits before it reports timeout, from 1s to 30s. The default is 5s.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show tracerouteRead-onlyTrace the network path from this router to a target.
show traceroute [dest <dest>] [max-hops <max-hops>] [timeout <timeout>] [probes <probes>] [do-not-fragment <honor-cache|bypass-cache>]

Argumentsdest string, required: no, any value of this type: Target host or IP address. The value is the first bare word of the command. A host name is resolved in either address family, and the family of the answer selects ICMPv4 or ICMPv6.
max-hops uint, required: no, any value of this type: Maximum number of hops. The value is the largest time-to-live Ze probes, 1 to 64. The trace stops early when the target answers. Absent, the value is 30.
timeout string, required: no, any value of this type: Timeout duration. The value is the time Ze waits for one probe, in Go duration syntax, 1s to 30s. Absent, the value is 3s.
probes uint, required: no, any value of this type: Number of probes per hop. The value is the number of probes Ze sends at each time-to-live, 1 to 10, and each probe reports its own round-trip time. Absent, the value is 3.
do-not-fragment enum, required: no, one of honor-cache bypass-cache: Set the Don't Fragment bit; honor-cache obeys the cached path MTU, bypass-cache ignores it. The keyword takes one of two values. honor-cache sets the Don't Fragment bit and honors the kernel's cached path MTU: a probe larger than the cached value is refused at send time, and a router's Fragmentation Needed answer updates the cache. bypass-cache sets the bit and ignores the cached value, so the probe is put on the wire at its full size. Absent, the kernel fragments a probe larger than the path, which is the behavior of before the keyword existed.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show uptimeRead-onlyShow how long the daemon has been running.
show uptime
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show versionRead-onlyShow the running Ze version and build date.
show version
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show warningsRead-onlyShow active warnings across all subsystems.
show warnings
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

show yang completionRead-onlyShow YANG paths available for tab completion.
show yang completion
15 operators · answer: tab

Answer shapetab

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

show yang docRead-onlyGenerate command reference docs from YANG schemas.
show yang doc
None
show yang treeRead-onlyPrint the YANG tree for a module in a readable hierarchy.
show yang tree
15 operators · answer: tab · 1 column order

Answer shapetab

Column ordername, kind, source, description

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save · match · count · first · last · display · fill

While streaminglog

Local process onlysave

skills 1
CommandModeDescriptionPipes
skillsOfflineList the agent skills this binary carries, or fetch one by name.None
support 1
CommandModeDescriptionPipes
supportOfflineCollect logs, config, state and diagnostics into one archive.None
system 8
CommandModeDescriptionPipes
system command completeRead-onlyList the completion candidates for a partial command.
system command complete <partial>

Argumentspartial string, required: yes, any value of this type: Partial command text The text typed so far. The candidates match it on a case-insensitive prefix, and a prefix that matches nothing answers an empty list.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

system command helpRead-onlyShow the detailed help for one command.
system command help <name>

Argumentsname string, required: yes, any value of this type: Command name The full command name, as command list prints it. A name in neither registry fails with unknown command.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

system command listRead-onlyList every command the daemon knows.
system command list
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

system dispatchRead-onlyDispatch a text command through the command dispatcher.
system dispatch
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

system helpRead-onlyList the subcommands the system verb accepts.
system help
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

system subsystem listRead-onlyList the subsystems registered in the daemon.
system subsystem list
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

system version apiRead-onlyShow the IPC protocol version.
system version api
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

system version softwareRead-onlyShow the ze software version.
system version software
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

update 16
CommandModeDescriptionPipes
update bgp configDaemonWrite the running peer set to the configuration file.
update bgp config
9 operators · answer: doc · 1 column order

Answer shapedoc

Column orderadded, removed, config, message

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

While streaminglog

Local process onlysave

update bgp irr allDaemonRefresh all IRR prefix-lists immediately.
update bgp irr all
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

update bgp irr as-setDaemonRefresh IRR prefix-list for a specific AS-SET.
update bgp irr as-set <as-set>

Argumentsas-set string, required: yes, any value of this type: AS-SET name. The AS-SET name as the peer configuration spells it, compared as an exact string. Every enrolled ASN that resolves through this AS-SET is refreshed, and a name no enrolled ASN uses is refused.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

update bgp irr asnDaemonRefresh IRR prefix-list for a specific ASN.
update bgp irr asn <asn>

Argumentsasn string, required: yes, any value of this type: ASN number. The AS number as a plain decimal from 0 to 4294967295. An ASN with no IRR-filtered peer is refused, and a refresh the IRR server fails is reported with the server's error.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

update bgp peer prefixDaemonRefresh max-prefix limits from PeeringDB.
update bgp peer <selector> prefix

Argumentsselector string, required: yes, any value of this type: Peer selector The value is an IP address, a peer name, an AS pattern such as as65001, a glob, or * for every peer. 'prefix' refreshes the maximums of each peer it matches.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

update firewall domain-groupDaemonResolve a domain group's DNS names now and program its set.
update firewall domain-group <name>

Argumentsname string, required: yes, any value of this type: Domain group name A group from the firewall configuration. Every name in that group is resolved, and a name no group carries is an error that lists the groups present.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

update firewall irr allDaemonRefresh all cached IRR prefix-lists.
update firewall irr all
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

update firewall irr as-setDaemonFetch or refresh IRR prefix-list for an AS-SET.
update firewall irr as-set <as-set>

Argumentsas-set string, required: yes, any value of this type: AS-SET name The RPSL set name, for example AS-EXAMPLE or RIPE::AS-EXAMPLE. Letters, digits, hyphen, underscore, colon and period are accepted, and the name is the cache key.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

update firewall irr asnDaemonFetch or refresh IRR prefix-list for an ASN.
update firewall irr asn <asn>

Argumentsasn string, required: yes, any value of this type: ASN number The AS number, 1 to 4294967294, in plain or dotted form. The cache key is the decimal spelling with an AS prefix, so 1.10 and 65546 name one entry.

15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

update resolve rirDaemonRefresh the RIR delegation table from the five registry delegation files.
update resolve rir
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

update serveOfflineServe this binary and its version manifest for update checks.None
update system firmware applyDaemonFull upgrade: download, verify, stage, and restart.
update system firmware apply
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

update system firmware checkDaemonCheck for a new firmware version right now.
update system firmware check
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

update system firmware downloadDaemonDownload the latest firmware image right now.
update system firmware download
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

update system firmware restartDaemonReboot into the already-staged firmware.
update system firmware restart
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

update system firmware rollbackDaemonRoll back to the previous firmware and restart.
update system firmware rollback
15 operators

Alwaysjson · ndjson · table · text · yaml · raw · no-more · save

With rowsmatch · count · first · last · display · fill

While streaminglog

Local process onlysave

validate 1
CommandModeDescriptionPipes
validate configOfflineCheck a config for errors without applying it.None