log first-packet

Function

The log first-packet command enables the logging of the first packet that matches an ACL rule.

The undo log first-packet command disables the logging of the first packet that matches an ACL rule.

By default, the logging of the first packet that matches an ACL rule is disabled.

Format

log first-packet

undo log first-packet

Parameters

None

Views

Traffic behavior view

Default Level

2: Configuration level

Task Name and Operations

Task Name Operations
qos write

Usage Guidelines

Usage Scenario

To detect the traffic that passes through the device, run the log first-packet command. When packets match an ACL, information about the first matching packet can be logged, including the name of the inbound/outbound interface, source IP address, destination IP address, protocol number, source port number, destination port number, time when the first packet is received (millisecond-level), and number of packets within the specified period.

Prerequisites

An unshared traffic policy has been configured.

You must execute the ip netstream sampler to slot self command to configure the sampling mode before configuring the log first-packet command.

Precautions

  • The log first-packet command supports logging only for IP packets. MPLS/L2/UCL rules are not supported.
  • If queue congestion occurs, the first packet recording time is inaccurate.
  • The shared traffic policy does not support the log first-packet command.
  • If a traffic policy is applied to Layer 2 interfaces ,EVC, VE or global VE, the traffic behavior in the traffic policy cannot be set to log first-packet command.
  • If the global ACL, global UCL, VPN ACL, or VXLAN multi-field classification has been configured on the device, log first-packet command cannot be configured.
  • If a traffic policy has been applied to a vBDIF, or GRE tunnel interface, log first-packet command cannot be configured.
  • In the same traffic behavior, the log first-packet command is mutually exclusive with the ip netstream sampler command.

Example

# Enable the logging of the first packet that matches an ACL rule.
<HUAWEI> system-view
[~HUAWEI] traffic behavior test
[*HUAWEI-behavior-test] log first-packet
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >