This feature is available as an add-on for the Honeycomb Enterprise plan.
Please contact your Honeycomb account team for details.
tcpdump on macOS/Linux, Npcap on Windows) to capture packets directly from a network interface.
Supported Platforms
| Platform | Metrics | Logs | Traces |
|---|---|---|---|
| macOS | ✓ | ||
| Linux | ✓ | ||
| Windows | ✓ |
Prerequisites
macOS/Linux
Tool:tcpdump is pre-installed on macOS and most Linux distributions. To verify:
Windows
Tool: Requires Npcap driver (included with Wireshark, or install standalone from Npcap).- Install Npcap (or install Wireshark which includes Npcap)
- List interfaces using PowerShell or the Npcap SDK tools
- Interface names on Windows use Npcap device paths (e.g.,
\Device\NPF_{GUID})
Configuration Table
| Parameter | Type | Default | Description |
|---|---|---|---|
| network_interface | string | "" | Network interface to capture packets from. |
| filter | string | "" | BPF (Berkeley Packet Filter) expression to filter packets. |
| parse_attributes | bool | true | The path to the dumpcap executable. Windows only (ignored on other platforms). |
| snaplen | int | 65535 | Maximum bytes to capture per packet (64-65535). |
| promiscuous | bool | true | Enable promiscuous mode to capture all network traffic. |
Interface Names
To list available interfaces on macOS/Linux:dumpcap executable:
Get-NetAdapter:
\NPF_