An IOS XE Embedded Packet Capture is started with 'monitor capture <name> start', stopped with 'monitor capture <name> stop', and saved for analysis with 'monitor capture <name> export <location>'.

Checked 2026-09-24

Vendor
Cisco
Product
IOS XE
Subsystem
Embedded Packet Capture
Deployment
on-premises
Region
not restricted
Release range
IOS XE 17.x
Checked
2026-09-24

Sources

Cite this note

APA

WarmTransfer. (2026, September 24). Analysing a SIP call in Wireshark: source note sip-call-analysis-wireshark-epc-start-stop-export. WarmTransfer. https://warmtransfer.net/knowledge/claims/sip-call-analysis-wireshark-epc-start-stop-export

BibTeX

@misc{warmtransfer-claim-sip-call-analysis-wireshark-epc-start-stop-export,
  title  = {Analysing a SIP call in Wireshark: source note sip-call-analysis-wireshark-epc-start-stop-export},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/sip-call-analysis-wireshark-epc-start-stop-export},
  note   = {Source note sip-call-analysis-wireshark-epc-start-stop-export, checked 2026-09-24}
}

Read in context