Network Observability CLI (oc netobserv) reference
Esc
Start typing to search...
On this page

Network Observability CLI (oc netobserv) reference

The Network Observability CLI (oc netobserv) provides feature and filtering parity with the Network Observability Operator. Use command-line arguments to dynamically toggle features and isolate specific cluster network traffic flows.

Network Observability CLI usage

You can use the Network Observability CLI (oc netobserv) to pass command line arguments to capture flows data, packets data, and metrics for further analysis and enable features supported by the Network Observability Operator.

Syntax

The basic syntax for oc netobserv commands:

oc netobserv syntax
$ oc netobserv [<command>] [<feature_option>] [<command_options>] (1)
  1. Feature options can only be used with the oc netobserv flows command. They cannot be used with the oc netobserv packets command.

Basic commands

Basic commands

CommandDescription
flowsCapture flows information. For subcommands, see the "Flows capture options" table.
packetsCapture packets data. For subcommands, see the "Packets capture options" table.
metricsCapture metrics data. For subcommands, see the "Metrics capture options" table.
followFollow collector logs when running in background.
stopStop collection by removing agent daemonset.
copyCopy collector generated files locally.
cleanupRemove the Network Observability CLI components.
versionPrint the software version.
helpShow help.

Flows capture options

Flows capture has mandatory commands as well as additional options, such as enabling extra features about packet drops, DNS latencies, Round-trip time, and filtering.

oc netobserv flows syntax
$ oc netobserv flows [<feature_option>] [<command_options>]
OptionDescriptionDefault
--enable_allenable all eBPF featuresfalse
--enable_dnsenable DNS trackingfalse
--enable_ipsecenable IPsec trackingfalse
--enable_network_eventsenable network events monitoringfalse
--enable_pkt_translationenable packet translationfalse
--enable_pkt_dropenable packet dropfalse
--enable_rttenable RTT trackingfalse
--enable_udn_mappingenable User Defined Network mappingfalse
--get-subnetsget subnets informationfalse
--privilegedforce eBPF agent privileged modeauto
--samplingpackets sampling interval1
--backgroundrun in backgroundfalse
--copycopy the output files locallyprompt
--log-levelcomponents logsinfo
--max-timemaximum capture time5m
--max-bytesmaximum capture bytes50000000 = 50MB
--actionfilter actionAccept
--cidrfilter CIDR0.0.0.0/0
--directionfilter direction-
--dportfilter destination port-
--dport_rangefilter destination port range-
--dportsfilter on either of two destination ports-
--dropsfilter flows with only dropped packetsfalse
--icmp_codefilter ICMP code-
--icmp_typefilter ICMP type-
--node-selectorcapture on specific nodes-
--peer_ipfilter peer IP-
--peer_cidrfilter peer CIDR-
--port_rangefilter port range-
--portfilter port-
--portsfilter on either of two ports-
--protocolfilter protocol-
--queryfilter flows using a custom query-
--sport_rangefilter source port range-
--sportfilter source port-
--sportsfilter on either of two source ports-
--tcp_flagsfilter TCP flags-
--interfaceslist of interfaces to monitor, comma separated-
--exclude_interfaceslist of interfaces to exclude, comma separatedlo
Example running flows capture on TCP protocol and port 49051 with PacketDrop and RTT features enabled:
$ oc netobserv flows --enable_pkt_drop  --enable_rtt --action=Accept --cidr=0.0.0.0/0 --protocol=TCP --port=49051

Packets capture options

You can filter packets capture data the as same as flows capture by using the filters. Certain features, such as packets drop, DNS, RTT, and network events, are only available for flows and metrics capture.

oc netobserv packets syntax
$ oc netobserv packets [<option>]
OptionDescriptionDefault
--backgroundrun in backgroundfalse
--copycopy the output files locallyprompt
--log-levelcomponents logsinfo
--max-timemaximum capture time5m
--max-bytesmaximum capture bytes50000000 = 50MB
--actionfilter actionAccept
--cidrfilter CIDR0.0.0.0/0
--directionfilter direction-
--dportfilter destination port-
--dport_rangefilter destination port range-
--dportsfilter on either of two destination ports-
--dropsfilter flows with only dropped packetsfalse
--icmp_codefilter ICMP code-
--icmp_typefilter ICMP type-
--node-selectorcapture on specific nodes-
--peer_ipfilter peer IP-
--peer_cidrfilter peer CIDR-
--port_rangefilter port range-
--portfilter port-
--portsfilter on either of two ports-
--protocolfilter protocol-
--queryfilter flows using a custom query-
--sport_rangefilter source port range-
--sportfilter source port-
--sportsfilter on either of two source ports-
--tcp_flagsfilter TCP flags-
Example running packets capture on TCP protocol and port 49051:
$ oc netobserv packets --action=Accept --cidr=0.0.0.0/0 --protocol=TCP --port=49051

Metrics capture options

You can enable features and use filters on metrics capture, the same as flows capture. The generated graphs fill accordingly in the dashboard.

oc netobserv metrics syntax
$ oc netobserv metrics [<option>]
OptionDescriptionDefault
--enable_allenable all eBPF featuresfalse
--enable_dnsenable DNS trackingfalse
--enable_ipsecenable IPsec trackingfalse
--enable_network_eventsenable network events monitoringfalse
--enable_pkt_translationenable packet translationfalse
--enable_pkt_dropenable packet dropfalse
--enable_rttenable RTT trackingfalse
--enable_udn_mappingenable User Defined Network mappingfalse
--get-subnetsget subnets informationfalse
--privilegedforce eBPF agent privileged modeauto
--samplingpackets sampling interval1
--backgroundrun in backgroundfalse
--log-levelcomponents logsinfo
--max-timemaximum capture time1h
--actionfilter actionAccept
--cidrfilter CIDR0.0.0.0/0
--directionfilter direction-
--dportfilter destination port-
--dport_rangefilter destination port range-
--dportsfilter on either of two destination ports-
--dropsfilter flows with only dropped packetsfalse
--icmp_codefilter ICMP code-
--icmp_typefilter ICMP type-
--node-selectorcapture on specific nodes-
--peer_ipfilter peer IP-
--peer_cidrfilter peer CIDR-
--port_rangefilter port range-
--portfilter port-
--portsfilter on either of two ports-
--protocolfilter protocol-
--queryfilter flows using a custom query-
--sport_rangefilter source port range-
--sportfilter source port-
--sportsfilter on either of two source ports-
--tcp_flagsfilter TCP flags-
--include_listlist of metric names to generate, comma separatednamespace_flows_total,node_ingress_bytes_total,node_egress_bytes_total,workload_ingress_bytes_total
--interfaceslist of interfaces to monitor, comma separated-
--exclude_interfaceslist of interfaces to exclude, comma separatedlo
Example running metrics capture for TCP drops
$ oc netobserv metrics --enable_pkt_drop --protocol=TCP