---
title: "Fast and simple troubleshooting with GUI-based Dynamic Packet Capture"
source: "https://www.tigera.io/blog/fast-and-simple-troubleshooting-with-gui-based-dynamic-packet-capture/"
---

[Technical Blog](https://www.tigera.io/category/technical-blog/)

# Fast and simple troubleshooting with GUI-based Dynamic Packet Capture

By [Joseph Yostos](https://www.tigera.io/blog/author/joseph-yostos/) on Nov 03, 2021 • 3 min read

With the Calico Enterprise 3.10 release, Dynamic Packet Capture is available in Dynamic Service Graph.

This means users who require self-service, live troubleshooting for microservices and Kubernetes workloads can capture and evaluate traffic packets on endpoints without writing a single line of code or using any 3rd-party troubleshooting tools. Users don’t need to learn about or have knowledge of kubectl or YAML to troubleshoot their microservices and Kubernetes cluster. Calico helps enforce organizational security policies by only allowing users to access their assigned namespaces and endpoints for troubleshooting.

## About Dynamic Packet Capture

In most situations when you need to do a packet capture, the problem doesn’t last long and usually happens randomly. But once you narrow down the issue to a particular time or activity, you will need to set the right action plan to tackle the problem. Packet capture is now much easier, simpler, and faster than before.

Dynamic Packet Capture facilitates fast troubleshooting and easy debugging of microservice connectivity issues and performance hotspots in Kubernetes clusters. It is a Kubernetes-native custom resource that runs as part of user code against specific workloads in the cluster, without the need to execute any programs inside the cluster. Dynamic Packet Capture integrates with Kubernetes rule-based access control (RBAC), which allows teams to troubleshoot workloads within their own namespaces without affecting the rest of the Kubernetes cluster. Additionally, within the same cluster or namespace, the RBAC integration helps differentiate between who can run the packet capture and who can retrieve the captured files.

## Four things you can do with Dynamic Packet Capture

Users can now take advantage of Dynamic Packet Capture in the following four ways:

- Run packet capture whenever you want (available 24/7)

- Preschedule packet captures to start and stop when needed

- Customize packet captures according to port, protocol, and namespace

- Share and collaborate packet capture jobs

### Run packet capture whenever you want (available 24/7)

With Dynamic Packet Capture in Dynamic Service Graph, all it takes is a single click to start a packet capture based on the user’s role assigned in the namespace.

Let’s see how it works!

Complete the following steps to run a packet capture:

- Select an endpoint from the dynamic service graph.

- From the service graph view, select the namespace, **right-click**, and select **initiate packet capture**.

![Service graph showing right-click menu on a namespace with 'Initiate packet capture' highlighted](https://www.tigera.io/app/uploads/2021/11/service-graph.png)

### Preschedule packet captures to start and stop when needed

Schedule a traffic capture for 5 minutes between 3:32 UTC and 3:37 UTC for all workload endpoints in the sample namespace.

![Screenshot of packet capture settings: job name, default namespace, start/end times, TCP protocol, port 80](https://www.tigera.io/app/uploads/2021/11/service-graph-packet-capture.png)

### Customize packet captures according to port, protocol, and namespace

Give the packet capture job a name and select a time interval, port, and protocol. Then click **Run**.

![The Packet Capture form with fields for job name, namespace, start and end time, protocol, and port. Run and Cancel buttons](https://www.tigera.io/app/uploads/2021/11/service-graph-packet-capture-2.jpg)

### Share and collaborate packet capture jobs

From the Capture Jobs tab in the bottom panel, you can:

- Rerun/stop a capture job

- Retrieve and delete capture files

- View YAML files

- Delete a capture job

![Screenshot showing options to rerun, download YAML, captures, or delete a capture job](https://www.tigera.io/app/uploads/2021/11/service-graph-2-1024x482.png)

 

## Conclusion

Now you have everything you need to troubleshoot your microservices and applications quickly and efficiently. If you prefer to have packet capture as part of your code, refer to the example of the packet capture manifest files in [this article](http://thenewstack.io/faster-troubleshooting-with-dynamic-packet-capture/).

 

***Ready to try Dynamic Packet Capture for yourself? Get started with a free [Calico Cloud trial](http://www.calicocloud.io/).***

 

[How-To](https://www.tigera.io/tags/how-to/)[Products](https://www.tigera.io/tags/products/)

## Related posts

[![Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/app/uploads/2026/09/Meet-Mylo-An-AI-native-way-to-work-with-Calico.png)](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

#### [Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

By [Phil DiCorpo](https://www.tigera.io/blog/author/phil-dicorpo/)
on Sep 3, 2026

A library of Calico tools and skills — delivered through the Calico MCP Server What if your hardest network question took ten minutes instead of ten days? Anyone who has operated Kubernetes networking at scale...

[Read more](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[![The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/app/uploads/2026/08/The-Safest-Place-to-Run-an-AI-Agent-Is-On-a-Cluster-That-Doesnt-Trust-It.png)](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

#### [The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 27, 2026

Every organization running AI agents has already made a hosting decision. Most made it by accident. The sales team switched on the agent built into their CRM. Engineering is piloting a coding agent in a...

[Read more](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

[![AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/app/uploads/2026/08/AI-Red-Team-Agents-Automate-Attacks-on-your-AI-Agents.-Runtime-Policies-Automate-their-Defense.png)](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

#### [AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 24, 2026

The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms...

[Read more](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=3364 metric#misses=35 metric#hit-ratio=99.0 metric#bytes=1476406 metric#prefetches=159 metric#store-reads=47 metric#store-writes=15 metric#store-hits=167 metric#store-misses=24 metric#sql-queries=32 metric#ms-total=608.64 metric#ms-cache=19.04 metric#ms-cache-avg=0.3121 metric#ms-cache-ratio=3.1 sample#redis-hits=2062002 sample#redis-misses=727157 sample#redis-hit-ratio=73.9 sample#redis-ops-per-sec=19 sample#redis-evicted-keys=0 sample#redis-used-memory=146705240 sample#redis-used-memory-rss=118239232 sample#redis-memory-fragmentation-ratio=0.8 sample#redis-connected-clients=1 sample#redis-tracking-clients=0 sample#redis-rejected-connections=0 sample#redis-keys=120344 -->
