Command map

show capture interface

Capture live packets on an interface (like tcpdump).

Ze command

Registry path
show capture interface
Usage
show capture interface [iface <iface>] [count <count>] [duration <duration>] [snap-len <snap-len>] [format <pcap|text>] [protocol <protocol>]
Mode
Read-only
Wire method
ze-show:capture-interface
Backends
any backend
Task support
optional: the MCP call is synchronous, which is the default
Subcommands
none: this command takes no subcommand
Pipes, always
json, ndjson, table, text, yaml, raw, no-more, save
Pipes, when the answer has rows
match, count, first, last, display, fill
Pipes, while streaming
log
Pipes, local process only
save

Description

Uses AF_PACKET for zero-copy capture. Filter by protocol and port. Limit with
count or duration. Output as pcap (for Wireshark) or text. Snap-len controls
how many bytes per packet are captured.

Arguments

NameTypeRequiredValuesSummaryDescription
ifacestringnoany value of this typeInterface name.The interface name as the configuration spells it. Ze resolves it to the kernel device before it opens the socket. One capture at a time runs per interface, and a second call on the same name is refused.
countuintnoany value of this typePacket count.The capture ends when this many packets have been read or when the duration has elapsed, whichever comes first. The default is 100.
durationstringnoany value of this typeCapture duration.The time the socket stays open, from 1s to 60s. The default is 10s. The capture ends earlier when the packet count is reached.
snap-lenuintnoany value of this typeSnap length in bytes.The number of bytes kept from the start of each packet. The default is 65535, which keeps whole packets. The value is written into the pcap file header.
formatenumnopcap textOutput format.The default is pcap. Both forms carry a packets count with the data.
protocolstringnoany value of this typeProtocol filter.A pcap-filter word such as tcp or udp. Ze joins it to every other word after the interface name and compiles the whole expression to a BPF program on the socket.

Mapping status

No vendor equivalent has been curated yet for this Ze command.

Juniper Junos MX

No equivalent is listed for this vendor yet.

Cisco IOS XR

No equivalent is listed for this vendor yet.

Nokia SR OS

No equivalent is listed for this vendor yet.

VyOS

No equivalent is listed for this vendor yet.