---
title: PCAPs
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[Magic Transit](https://developers.cloudflare.com/api/go/resources/magic_transit)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# PCAPs

##### [List packet capture requests](https://developers.cloudflare.com/api/go/resources/magic_transit/subresources/pcaps/methods/list)

client.MagicTransit.PCAPs.List(ctx, query) (\*SinglePage\[[PCAPListResponse](<https://developers.cloudflare.com/api/go/resources/magic_transit#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/pcaps

##### [Get PCAP request](https://developers.cloudflare.com/api/go/resources/magic_transit/subresources/pcaps/methods/get)

client.MagicTransit.PCAPs.Get(ctx, pcapID, query) (\*[PCAPGetResponse](<https://developers.cloudflare.com/api/go/resources/magic_transit#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPGetResponse%20%3E%20(schema)>), error)

GET/accounts/{account\_id}/pcaps/{pcap\_id}

##### [Create PCAP request](https://developers.cloudflare.com/api/go/resources/magic_transit/subresources/pcaps/methods/create)

client.MagicTransit.PCAPs.New(ctx, params) (\*[PCAPNewResponse](<https://developers.cloudflare.com/api/go/resources/magic_transit#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/pcaps

##### [Stop full PCAP](https://developers.cloudflare.com/api/go/resources/magic_transit/subresources/pcaps/methods/stop)

client.MagicTransit.PCAPs.Stop(ctx, pcapID, body) error

PUT/accounts/{account\_id}/pcaps/{pcap\_id}/stop

##### ModelsExpand Collapse

<details>

<summary>

type PCAP struct{…}

</summary>

ID stringOptional

The ID for the packet capture.

maxLength32

minLength32

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

FilterV1 <a href="https://developers.cloudflare.com/api/go/resources/magic_transit#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)">PCAPFilter</a>Optional

The packet capture filter. When this field is empty, all packets are captured.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20filter_v1">Link to this property</a>

OffsetTime TimeOptional

The RFC 3339 offset timestamp from which to query backwards for packets. Must be within the last 24h. When this field is empty, defaults to time of request.

formatdate-time

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20offset_time">Link to this property</a>

<details>

<summary>

Status PCAPStatusOptional

The status of the packet capture request.

</summary>

One of the following:

const PCAPStatusUnknown PCAPStatus = "unknown"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

const PCAPStatusSuccess PCAPStatus = "success"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

const PCAPStatusPending PCAPStatus = "pending"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

const PCAPStatusRunning PCAPStatus = "running"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

const PCAPStatusConversionPending PCAPStatus = "conversion\_pending"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

const PCAPStatusConversionRunning PCAPStatus = "conversion\_running"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%205">Link to this property</a>

const PCAPStatusComplete PCAPStatus = "complete"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%206">Link to this property</a>

const PCAPStatusFailed PCAPStatus = "failed"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

Submitted stringOptional

The RFC 3339 timestamp when the packet capture was created.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20submitted">Link to this property</a>

System PCAPSystemOptional

The system used to collect packet captures.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20system">Link to this property</a>

TimeLimit float64Optional

The packet capture duration in seconds.

maximum300

minimum1

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20time_limit">Link to this property</a>

<details>

<summary>

Type PCAPTypeOptional

The type of packet capture. <code>Simple</code> captures sampled packets, and <code>full</code> captures entire payloads and non-sampled packets.

</summary>

One of the following:

const PCAPTypeSimple PCAPType = "simple"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

const PCAPTypeFull PCAPType = "full"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)>)

<details>

<summary>

type PCAPFilter struct{…}

The packet capture filter. When this field is empty, all packets are captured.

</summary>

DestinationAddress stringOptional

The destination IP address of the packet.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)%20%3E%20(property)%20destination_address">Link to this property</a>

DestinationPort float64Optional

The destination port of the packet.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)%20%3E%20(property)%20destination_port">Link to this property</a>

Protocol float64Optional

The protocol number of the packet.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)%20%3E%20(property)%20protocol">Link to this property</a>

SourceAddress stringOptional

The source IP address of the packet.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)%20%3E%20(property)%20source_address">Link to this property</a>

SourcePort float64Optional

The source port of the packet.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)%20%3E%20(property)%20source_port">Link to this property</a>

</details>

[Link to this property](<#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)>)

#### PCAPsOwnership

##### [List PCAPs Bucket Ownership](https://developers.cloudflare.com/api/go/resources/magic_transit/subresources/pcaps/subresources/ownership/methods/get)

client.MagicTransit.PCAPs.Ownership.Get(ctx, query) (\*SinglePage\[[Ownership](<https://developers.cloudflare.com/api/go/resources/magic_transit#(resource)%20magic_transit.pcaps.ownership%20%3E%20(model)%20ownership%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/pcaps/ownership

##### [Add buckets for full packet captures](https://developers.cloudflare.com/api/go/resources/magic_transit/subresources/pcaps/subresources/ownership/methods/create)

client.MagicTransit.PCAPs.Ownership.New(ctx, params) (\*[Ownership](<https://developers.cloudflare.com/api/go/resources/magic_transit#(resource)%20magic_transit.pcaps.ownership%20%3E%20(model)%20ownership%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/pcaps/ownership

##### [Delete buckets for full packet captures](https://developers.cloudflare.com/api/go/resources/magic_transit/subresources/pcaps/subresources/ownership/methods/delete)

client.MagicTransit.PCAPs.Ownership.Delete(ctx, ownershipID, body) error

DELETE/accounts/{account\_id}/pcaps/ownership/{ownership\_id}

##### [Validate buckets for full packet captures](https://developers.cloudflare.com/api/go/resources/magic_transit/subresources/pcaps/subresources/ownership/methods/validate)

client.MagicTransit.PCAPs.Ownership.Validate(ctx, params) (\*[Ownership](<https://developers.cloudflare.com/api/go/resources/magic_transit#(resource)%20magic_transit.pcaps.ownership%20%3E%20(model)%20ownership%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/pcaps/ownership/validate

##### ModelsExpand Collapse

<details>

<summary>

type Ownership struct{…}

</summary>

ID string

The bucket ID associated with the packet captures API.

maxLength32

minLength32

<a href="#(resource)%20magic_transit.pcaps.ownership%20%3E%20(model)%20ownership%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

DestinationConf string

The full URI for the bucket. This field only applies to <code>full</code> packet captures.

<a href="#(resource)%20magic_transit.pcaps.ownership%20%3E%20(model)%20ownership%20%3E%20(schema)%20%3E%20(property)%20destination_conf">Link to this property</a>

Filename string

The ownership challenge filename stored in the bucket.

<a href="#(resource)%20magic_transit.pcaps.ownership%20%3E%20(model)%20ownership%20%3E%20(schema)%20%3E%20(property)%20filename">Link to this property</a>

<details>

<summary>

Status OwnershipStatus

The status of the ownership challenge. Can be pending, success or failed.

</summary>

One of the following:

const OwnershipStatusPending OwnershipStatus = "pending"

<a href="#(resource)%20magic_transit.pcaps.ownership%20%3E%20(model)%20ownership%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

const OwnershipStatusSuccess OwnershipStatus = "success"

<a href="#(resource)%20magic_transit.pcaps.ownership%20%3E%20(model)%20ownership%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

const OwnershipStatusFailed OwnershipStatus = "failed"

<a href="#(resource)%20magic_transit.pcaps.ownership%20%3E%20(model)%20ownership%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20magic_transit.pcaps.ownership%20%3E%20(model)%20ownership%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

Submitted string

The RFC 3339 timestamp when the bucket was added to packet captures API.

<a href="#(resource)%20magic_transit.pcaps.ownership%20%3E%20(model)%20ownership%20%3E%20(schema)%20%3E%20(property)%20submitted">Link to this property</a>

Validated stringOptional

The RFC 3339 timestamp when the bucket was validated.

<a href="#(resource)%20magic_transit.pcaps.ownership%20%3E%20(model)%20ownership%20%3E%20(schema)%20%3E%20(property)%20validated">Link to this property</a>

</details>

[Link to this property](<#(resource)%20magic_transit.pcaps.ownership%20%3E%20(model)%20ownership%20%3E%20(schema)>)

#### PCAPsDownload

##### [Download Simple PCAP](https://developers.cloudflare.com/api/go/resources/magic_transit/subresources/pcaps/subresources/download/methods/get)

client.MagicTransit.PCAPs.Download.Get(ctx, pcapID, query) (\*Response, error)

GET/accounts/{account\_id}/pcaps/{pcap\_id}/download