---
title: "Enabling Automated Traffic Capture"
canonical: "https://docs.infoblox.com/space/nios85/35881827/Enabling%20Automated%20Traffic%20Capture"
format: markdown
---
Sometimes, there may be a sudden and unexplained change in the KPIs (Key Performance Indicators) in your network that may degrade your network performance and traffic capture during these events may not be available. For example, the cache hit ratio may drop below the configured value, or there may be an <span style="color: #333333">increase in authoritative delay. </span>

You can configure NIOS so that a traffic capture may be triggered based on thresholds configured for DNS Cache Hit Ratio and Queries Per Seconds. You can then analyse the traffic capture data and use it to gather production data thus bringing down the time taken for root cause analysis. You can also attach the traffic capture data to a support case so that Infoblox Support can take the investigation forward.

You can choose to receive an SNMP trap or an email notification every time traffic capture is enabled or disabled or a support bundle is downloaded. For more information see, <span style="color: #0000ff">[*Configuring SNMP*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35385484)</span>. 

> ⚠️ **Note**
> ⚠️ 
> ⚠️ If DNS Cache Acceleration is enabled on the IB-FLEX platform, the cache hit ratio is not updated for a minute thus triggering a false traffic capture.

To configure automated traffic capture:

1. <span style="color: #000000">From the </span>**<span style="color: #333333">Grid</span>**<span style="color: #000000"> tab, select the </span>**<span style="color: #333333">Grid</span>****<span style="color: #333333"> Manager</span>**<span style="color: #000000"> tab -> </span><span style="color: #000000">click </span>**<span style="color: #333333">Grid Properties</span>**<span style="color: #000000"> </span><span style="color: #000000">-></span><span style="color: #000000"> </span>**<span style="color: #000000">Edit</span>**<span style="color: #000000"> from the Toolbar.</span>  
<span style="color: #000000">Or to configure automated traffic capture for a member, f</span><span style="color: #000000">rom the </span>**<span style="color: #000000">Grid</span>**<span style="color: #000000"> tab, select the </span>**<span style="color: #000000">Grid</span>****<span style="color: #000000"> Manager</span>**<span style="color: #000000"> tab -> </span>**<span style="color: #000000">Members</span>**<span style="color: #000000"> tab </span><span style="color: #000000">-></span><span style="color: #000000"> select the member </span><span style="color: #000000">-></span><span style="color: #000000"> click the Action icon and click </span>**<span style="color: #000000">Edit</span>**<span style="color: #000000">.</span>
2. <span style="color: #333333">In </span>*<span style="color: #333333">Grid Properties Editor (for Grid) </span>*<span style="color: #333333">or</span>*<span style="color: #333333"> Grid Member Properties Editor</span>*<span style="color: #333333"> (for members), click </span>**<span style="color: #333333">Monitoring</span>**<span style="color: #333333"> </span><span style="color: #000000">-></span><span style="color: #333333"> </span>**<span style="color: #333333">Advanced</span>**<span style="color: #333333"> tab.</span>
3. <span style="color: #333333">Select the </span>**<span style="color: #333333">Enable Automated Traffic Capture</span>**<span style="color: #333333"> checkbox.</span>
4. <span style="color: #333333">In the </span>**<span style="color: #333333">Capture Duration</span>**<span style="color: #333333"> field, enter the number of seconds for which traffic must be captured. For example, if you enter 30 in the </span>**<span style="color: #333333">Capture Duration</span>**<span style="color: #333333"> field</span><span style="color: #333333">, traffic is captured for 30 seconds and stored in the traffic capture file. After 30 seconds, traffic is captured once again and the details are stored in a new traffic capture file. A new traffic capture is started only after the earlier traffic capture file is packaged. You can set a value from 1 to 600 seconds.  </span>**<span style="color: #333333">Capture Duration</span>**<span style="color: #333333"> is a mandatory field. If the capture file exceeds 2 GB (for </span><span style="color: #000000">IB-40</span>*<span style="color: #000000">XX </span>*<span style="color: #000000">and PT-40</span>*<span style="color: #000000">XX </span>*<span style="color: #000000">appliances</span><span style="color: #000000">) and 1 GB (for all other appliances), NIOS stops the traffic capture.</span>
5. <span style="color: #333333">Select the </span>**<span style="color: #333333">Save Local Copy</span>**<span style="color: #333333"> checkbox to save traffic capture data in your local disk. </span>
6. <span style="color: #333333">Select the </span>**<span style="color: #333333">Include Support Bundle </span>**<span style="color: #333333">checkbox to </span><span style="color: #000000">download the support bundle after the traffic capture is complete and the system has remained in a stable state for 5 minutes.</span>
7. <span style="color: #000000">From the </span>**<span style="color: #000000">Export to</span>**<span style="color: #000000"> drop-down list, select </span><span style="color: #000000">your local management system (FTP server or SCP server) to which to </span><span style="color: #000000">transfer the traffic capture file. The default is </span>**<span style="color: #000000">None</span>**<span style="color: #000000">.</span>
8. <span style="color: #000000">In the </span>**<span style="color: #000000">Directory Path For Capture</span>**<span style="color: #000000"> field, enter the d</span><span style="color: #000000">estination directory on the NIOS server for which to transfer the traffic capture files. </span>
9. <span style="color: #000000">In the </span>**<span style="color: #000000">Directory Path For Support Bundle </span>**<span style="color: #000000">field, enter the d</span><span style="color: #000000">estination directory on the NIOS server for which to transfer the support bundles. </span>
10. <span style="color: #001000">In the </span>**<span style="color: #001000">Server Address</span>**<span style="color: #001000"> field, enter the IP address of the FTP or the SCP server that you selected f</span><span style="color: #000000">rom the </span>**<span style="color: #001000">Export to</span>**<span style="color: #000000"> drop-down list.</span>
11. <span style="color: #000000">In the </span>**<span style="color: #000000">Username</span>**<span style="color: #000000"> and </span>**<span style="color: #000000">Password</span>**<span style="color: #000000"> fields, enter the u</span><span style="color: #000000">ser credentials to upload to the FTP or SCP server.</span>
12. <span style="color: #333333">Select the </span>**<span style="color: #333333">Enable Cache Hit Ratio Trigger</span>**<span style="color: #333333"> checkbox if you want NIOS to trigger a traffic capture based on the value of the cache hit ratio of recursive queries. </span><span style="color: #333333">If the cache utilization goes above the value </span><span style="color: #333333">you specify in the </span>**<span style="color: #333333">Cache Utilization</span>**<span style="color: #333333"> field</span><span style="color: #333333"> and the </span><span style="color: #333333">cache hit ratio goes below the value you specify in the </span>**<span style="color: #333333">Hit Ratio Threshold Trigger</span>**<span style="color: #333333"> field, traffic capture is triggered. </span><span style="color: #333333">Once  the </span><span style="color: #333333">cache hit ratio reaches the value you specify in the </span>**<span style="color: #333333">Reset</span>**<span style="color: #333333"> field, NIOS stops the traffic capture. </span>
13. <span style="color: #333333">Select the </span>**Enable Queries Per Second Trigger**<span style="color: #333333"> checkbox if you want NIOS to monitor the QPS (queries per second). NIOS triggers a traffic capture if the QPS value goes below the threshold value you specify in the </span>**<span style="color: #333333">QPS Threshold Trigger</span>**<span style="color: #333333"> field. Once</span><span style="color: #000000"> the QPS value reaches the value you specify in the </span>**<span style="color: #000000">Reset</span>**<span style="color: #000000"> field, NIOS stops the traffic capture. </span><span style="color: #000000">For information about QPS, see </span><span style="color: #0000ff">[*About Dashboards.*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35751081)</span>
14. Select the **Enable Outgoing Recursive Queries Trigger** checkbox if you want NIOS to <span style="color: #000000">monitor the count of concurrent outgoing recursive queries. NIOS triggers a traffic capture if the count goes above the value you specify in the </span>**<span style="color: #000000">Recursive Queries Threshold Trigger</span>**<span style="color: #333333"> field</span><span style="color: #000000">. If the number of concurrent recursive queries goes below the value you specify in the </span>**<span style="color: #000000">Reset</span>**<span style="color: #000000"> field, NIOS stops the traffic capture. For information about recursive queries, see </span><span style="color: #0000ff">[*Enabling Recursive Queries*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35448674)</span><span style="color: #000000">.</span>
15. Select the **Enable Authoritative DNS Latency Trigger** checkbox if you want NIOS to monitor the authoritative DNS latency. NIOS performs the DNS latency on the IPS address you choose from the **Query IP Address** field and triggers a traffic capture if the DNS latency goes above the value you specify in the **Authoritative DNS Latency Threshold Trigger** field. The DNS latency is determined by querying a reverse zone against the IP address you selected using the `dig` command. If the authoritative DNS query latency goes below the value you specify in the **Reset** field, NIOS stops the traffic capture. For information about DNS latency, see <span style="color: #0000ff">[*Enabling and Disabling DNS Alert Monitoring*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35481832/Monitoring+Tools#MonitoringTools-EnablingandDisablingDNSAlertMonitoring)</span>.
16. <span style="color: #333333">Select the </span>**Enable Recursive DNS Latency Trigger**<span style="color: #333333"> checkbox if you want NIOS to </span><span style="color: #333333">monitor the recursive DNS latency. NIOS performs the DNS latency on the IPS address you choose from the </span>**Query IP Address**<span style="color: #333333"> field and triggers a traffic capture if the DNS latency goes above the value you specify in the </span>**Recursive DNS Latency Threshold Trigger**<span style="color: #333333"> field.</span><span style="color: #333333"> The DNS latency is determined by querying each domain against the IP address you selected using the </span>`dig`<span style="color: #333333"> command. If the recursive DNS query latency goes below the value you specify in the </span>**Reset**<span style="color: #333333"> field, NIOS stops the traffic capture. For information about DNS latency, see </span><span style="color: #0000ff">[*Enabling and Disabling DNS Alert Monitoring*](https://infoblox-docs.atlassian.net/wiki/spaces/nios85/pages/35481832/Monitoring+Tools#MonitoringTools-EnablingandDisablingDNSAlertMonitoring)</span><span style="color: #333333">. </span>
17. Click **Save & Close**.