---
title: "Introducing Fast, Automated Packet Capture for Kubernetes"
source: "https://www.tigera.io/blog/introducing-fast-automated-packet-capture-for-kubernetes/"
description: "Calico Enterprise PacketCapture reduces the time and effort required for operators to rapidly and effectively troubleshoot a connectivity issue."
---

[Technical Blog](https://www.tigera.io/category/technical-blog/)

# Introducing Fast, Automated Packet Capture for Kubernetes

By [John Armstrong](https://www.tigera.io/blog/author/john-armstrong/) on Nov 10, 2020 • 3 min read

If you’re an SRE or on a DevOps team working with [Kubernetes](http://kubernetes.io/) and containers, you’ve undoubtedly encountered network connectivity issues with your microservices and workloads. Something is broken and you’re under pressure to fix it, quickly. And so you begin the tedious, manual process of identifying the issue using the observability tools at your disposal…namely metrics and logs. However, there are instances where you may need to go beyond these tools to confirm a potential bug with applications running in your cluster.

## What is packet capture?

Packet capture is a valuable technique for debugging microservices and application interaction in day-to-day operations and incident response. But generating pcap files to diagnose connectivity issues in Kubernetes clusters can be a frustrating exercise in a dynamic environment where hundreds, possibly thousands of pods are continually being created and destroyed.

First, you would need to identify on which node your workload is running, match your workload against its host-based interface, and then (with root access to the node) use [tcpdump](http://www.tcpdump.org/manpages/tcpdump.1.html) to generate a file for packet analysis. Then you would need to transfer the pcap files to your laptop and view them in [Wireshark](http://www.wireshark.org/). If this doesn’t initially generate the information you need to identify and resolve the issue, you may have to repeat it again, potentially on another node and interface.

## Calico’s packet capture for Kubernetes

Calico Enterprise from Tigera introduces a new resource type called *PacketCapture* that automates and simplifies this cumbersome process by providing a Kubernetes-native way to capture packets from your deployments. It also provides a command-line interface to easily transfer any generated pcap files distributed across nodes directly to your local machine for analysis with tools like Wireshark.

Utilizing the same label-based selectors that are used for network policies, Calico Enterprise *PacketCapture* can identify a single or multiple workload endpoints for capturing live traffic. *PacketCapture* generates pcap files on the nodes associated with pods targeted for packet capture, and automatically manages the data retention and collection of generated files in a secure way. This significantly reduces the effort and time required to perform packet capture and analysis, and ultimately resolve connectivity issues.

Additionally, RBAC can be enabled with *PacketCapture* and user permissions are enforced using the standard Kubernetes RBAC based on Role and RoleBindings within a namespace. This further reduces admin overhead and makes *PacketCapture* an ideal solution for self-service environments and DevOps and service owners who desire greater autonomy, but require some guardrails.

Packet capture in the context of Kubernetes is time consuming. Calico Enterprise’s automated, Kubernetes-native approach significantly reduces the time and effort it takes for operators to get the network diagnostics they need to rapidly and effectively troubleshoot a connectivity issue.

**Want to learn more?**

[**Free Online Training**](https://www.tigera.io/events/)

Access Live and On-Demand Kubernetes Training

[**Calico Enterprise – Free Trial**](https://www.calicocloud.io/home)

Kubernetes Networking, Security and Observability in Hybrid and Multi-Clouds

[Products](https://www.tigera.io/tags/products/)[Announcements](https://www.tigera.io/tags/announcements/)

## Related posts

[![Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/app/uploads/2026/09/Meet-Mylo-An-AI-native-way-to-work-with-Calico.png)](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

#### [Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

By [Phil DiCorpo](https://www.tigera.io/blog/author/phil-dicorpo/)
on Sep 3, 2026

A library of Calico tools and skills — delivered through the Calico MCP Server What if your hardest network question took ten minutes instead of ten days? Anyone who has operated Kubernetes networking at scale...

[Read more](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[![The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/app/uploads/2026/08/The-Safest-Place-to-Run-an-AI-Agent-Is-On-a-Cluster-That-Doesnt-Trust-It.png)](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

#### [The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 27, 2026

Every organization running AI agents has already made a hosting decision. Most made it by accident. The sales team switched on the agent built into their CRM. Engineering is piloting a coding agent in a...

[Read more](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

[![AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/app/uploads/2026/08/AI-Red-Team-Agents-Automate-Attacks-on-your-AI-Agents.-Runtime-Policies-Automate-their-Defense.png)](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

#### [AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 24, 2026

The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms...

[Read more](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=3336 metric#misses=42 metric#hit-ratio=98.8 metric#bytes=1485408 metric#prefetches=155 metric#store-reads=50 metric#store-writes=18 metric#store-hits=162 metric#store-misses=31 metric#sql-queries=32 metric#ms-total=488.59 metric#ms-cache=14.32 metric#ms-cache-avg=0.2137 metric#ms-cache-ratio=2.9 sample#redis-hits=51572648 sample#redis-misses=14746928 sample#redis-hit-ratio=77.8 sample#redis-ops-per-sec=135 sample#redis-evicted-keys=0 sample#redis-used-memory=131415776 sample#redis-used-memory-rss=123060224 sample#redis-memory-fragmentation-ratio=0.9 sample#redis-connected-clients=1 sample#redis-tracking-clients=0 sample#redis-rejected-connections=0 sample#redis-keys=71955 -->
