quick
tool/sniffer/quick
Type: Command
Shows the matching packets live, until you stop it with Q or for the time given in duration. The filter arguments are the filter-* settings of /tool/sniffer without the filter- prefix, and vlan-id for filter-vlan. Without filter arguments, the saved filters apply; with filter arguments, only the filters given apply, and the saved settings do not change. quick cannot run while the sniffer runs (already running). proplist selects the columns, for example proplist=interface,time,dir,src-address,dst-address,protocol,size. See Packet sniffer.
| Argument | Type | Description |
|---|---|---|
| rows | num | Maximum number of packets displayed in the output. Default: the quick-rows setting (20). |
| show-frame | bool | Whether to show the raw frame content in the output. Default: the quick-show-frame setting (no). |
| interface | object { interface: iface_enum } | Interface or list of interfaces to capture traffic on. A bridged packet shows once on the bridge and once on the bridge port when both are included. |
| mac-address | object { mac-address-element: super { ! , mac-address-with-mask: composite { mac: macAddr , mask: [ macAddr] } } } | Filter: capture only frames with a matching MAC address or MAC address with mask. |
| src-mac-address | object { mac-address-element: super { ! , mac-address-with-mask: composite { mac: macAddr , mask: [ macAddr] } } } | Filter: capture only frames with a matching source MAC address or MAC address with mask. |
| dst-mac-address | object { mac-address-element: super { ! , mac-address-with-mask: composite { mac: macAddr , mask: [ macAddr] } } } | Filter: capture only frames with a matching destination MAC address or MAC address with mask. |
| mac-protocol | object { mac-protocol-element: super { ! , protocol: alt { mac-protocol: enum () , protocol-number: num [ .. 65535] } } } | Filter: capture only frames with a matching MAC (L2) protocol. |
| ip-protocol | object { ip-protocol-element: super { ! , ip-protocol: enum () } } | Filter: capture only packets with a matching IP protocol. |
| ip-address | object { ip-address-element: super { ! , ip-address-with-mask: composite { ip: ipAddr , mask: [ num [ .. 32]] } } } | Filter: capture only packets with a matching IP address or subnet. |
| src-ip-address | object { ip-address-element: super { ! , ip-address-with-mask: composite { ip: ipAddr , mask: [ num [ .. 32]] } } } | Filter: capture only packets with a matching source IP address or subnet. |
| dst-ip-address | object { ip-address-element: super { ! , ip-address-with-mask: composite { ip: ipAddr , mask: [ num [ .. 32]] } } } | Filter: capture only packets with a matching destination IP address or subnet. |
| ipv6-address | object { ipv6-address-element: super { ! , ipv6-prefix: ip6Prefix } } | Filter: capture only packets with a matching IPv6 address or prefix. |
| src-ipv6-address | object { ipv6-address-element: super { ! , ipv6-prefix: ip6Prefix } } | Filter: capture only packets with a matching source IPv6 address or prefix. |
| dst-ipv6-address | object { ipv6-address-element: super { ! , ipv6-prefix: ip6Prefix } } | Filter: capture only packets with a matching destination IPv6 address or prefix. |
| port | object { port-element: super { ! , port: enum () } } | Filter: capture only packets with a matching source or destination port. |
| src-port | object { port-element: super { ! , port: enum () } } | Filter: capture only packets with a matching source port. |
| dst-port | object { port-element: super { ! , port: enum () } } | Filter: capture only packets with a matching destination port. |
| vlan-id | object { vlan-element: super { ! , vlan: num [ .. 4095] } } | Filter: capture only frames with a matching VLAN ID. |
| direction | enum (any | tx | rx) { any:0, tx:1, rx:2 } | Filter: directions to capture.
|
| operator-between-entries | enum (or | and) { or:0, and:1 } | How the entries of one filter are combined.
|
| cpu | object { cpu-element: super { ! , cpu: num } } | Filter: capture only packets processed by the given CPU core. |
| size | object { size-element: super { ! , size-range: range [0 .. 65535] } } | Filter: capture only packets with a matching size or size range in bytes. |
| Read-only Argument | Type | Description |
|---|---|---|
| interface | iface_enum | Interface on which the packet was captured. |
| time | num | Time offset of the packet relative to the start of the capture, in seconds with microsecond precision. |
| num | num | Packet sequence number, starting from 0 for the first captured packet. |
| dir | enum (<- | ->) { <-:0, ->:1 } | Direction of the packet, <- received, -> sent. |
| src-mac | macAddr | Source MAC address of the frame, shown only for interfaces that have a MAC address, for example Ethernet, WiFi, EoIP, VXLAN or VLAN. |
| dst-mac | macAddr | Destination MAC address of the frame, shown only for interfaces that have a MAC address, for example Ethernet, WiFi, EoIP, VXLAN or VLAN. |
| vlan | composite { id: num [ .. 4095] , priority: num [ .. 7] } | VLAN tag of the frame, displayed as id:priority. |
| src-address | composite { address: alt { ip: ipAddr , ipv6: ip6Addr , descr: string } , port: enum () } | Source IP address and source port of the packet, displayed as address:port. |
| dst-address | composite { address: alt { ip: ipAddr , ipv6: ip6Addr } , port: enum () } | Destination IP address and destination port of the packet, displayed as address:port. |
| protocol | composite { mac-protocol: enum () , ip-protocol: enum (ip) { ip:0 } } | MAC (L2) protocol of the frame and its IP protocol, for example ip:icmp. |
| size | num | Total frame size in bytes, including the L2 header. |
| cpu | num | CPU core on which the packet was processed. |
| fp | bool | Whether the packet was processed in the fast path. |
| raw | string | Raw frame content in hexadecimal format, shown when the show-frame parameter is enabled. |
| dscp | num | DSCP (Differentiated Services Code Point) field of the IP header. |
| ecn | num | ECN (Explicit Congestion Notification) field of the IP header. |
| fragment-offset | num | Fragment offset field of the IP header. |
| identification | num | Identification field of the IP header. |
| ip-header-size | num | Size of the IP header in bytes. |
| ip-packet-size | num | Size of the IP packet in bytes. |
| tcp-flags | super { tcp-flags: multi { array-id, flag: enum (fin | syn | rst | psh | ack | urg | ece | cwr) { fin:0, syn:1, rst:2, psh:3, ack:4, urg:5, ece:6, cwr:7 } } } | TCP flags of the packet: fin, syn, rst, psh, ack, urg, ece or cwr. |
| ttl | num | Time to live field of the IP header. |