---
title: List packet capture requests
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[Magic Transit](https://developers.cloudflare.com/api/go/resources/magic_transit)

[PCAPs](https://developers.cloudflare.com/api/go/resources/magic_transit/subresources/pcaps)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# List packet capture requests

client.MagicTransit.PCAPs.List(ctx, query) (\*SinglePage\[[PCAPListResponse](<https://developers.cloudflare.com/api/go/resources/magic_transit#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)>)], error)

GET/accounts/{account\_id}/pcaps

Lists all packet capture requests for an account.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Magic Firewall Packet Captures - Write PCAPs API``Magic Firewall Packet Captures - Read PCAPs API`

##### ParametersExpand Collapse

<details>

<summary>

query PCAPListParams

</summary>

AccountID param.Field\[string]

Identifier.

maxLength32

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20account_id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20magic_transit.pcaps%20%3E%20(method)%20list%20%3E%20(params)%20default>)

##### ReturnsExpand Collapse

<details>

<summary>

type PCAPListResponse interface{…}

</summary>

One of the following:

<details>

<summary>

type PCAP struct{…}

</summary>

ID stringOptional

The ID for the packet capture.

maxLength32

minLength32

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

FilterV1 <a href="https://developers.cloudflare.com/api/go/resources/magic_transit#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)">PCAPFilter</a>Optional

The packet capture filter. When this field is empty, all packets are captured.

</summary>

DestinationAddress stringOptional

The destination IP address of the packet.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20filter_v1%20%2B%20(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)%20%3E%20(property)%20destination_address">Link to this property</a>

DestinationPort float64Optional

The destination port of the packet.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20filter_v1%20%2B%20(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)%20%3E%20(property)%20destination_port">Link to this property</a>

Protocol float64Optional

The protocol number of the packet.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20filter_v1%20%2B%20(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)%20%3E%20(property)%20protocol">Link to this property</a>

SourceAddress stringOptional

The source IP address of the packet.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20filter_v1%20%2B%20(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)%20%3E%20(property)%20source_address">Link to this property</a>

SourcePort float64Optional

The source port of the packet.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20filter_v1%20%2B%20(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)%20%3E%20(property)%20source_port">Link to this property</a>

</details>

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20filter_v1">Link to this property</a>

OffsetTime TimeOptional

The RFC 3339 offset timestamp from which to query backwards for packets. Must be within the last 24h. When this field is empty, defaults to time of request.

formatdate-time

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20offset_time">Link to this property</a>

<details>

<summary>

Status PCAPStatusOptional

The status of the packet capture request.

</summary>

One of the following:

const PCAPStatusUnknown PCAPStatus = "unknown"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

const PCAPStatusSuccess PCAPStatus = "success"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

const PCAPStatusPending PCAPStatus = "pending"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

const PCAPStatusRunning PCAPStatus = "running"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

const PCAPStatusConversionPending PCAPStatus = "conversion\_pending"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

const PCAPStatusConversionRunning PCAPStatus = "conversion\_running"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%205">Link to this property</a>

const PCAPStatusComplete PCAPStatus = "complete"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%206">Link to this property</a>

const PCAPStatusFailed PCAPStatus = "failed"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

Submitted stringOptional

The RFC 3339 timestamp when the packet capture was created.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20submitted">Link to this property</a>

System PCAPSystemOptional

The system used to collect packet captures.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20system">Link to this property</a>

TimeLimit float64Optional

The packet capture duration in seconds.

maximum300

minimum1

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20time_limit">Link to this property</a>

<details>

<summary>

Type PCAPTypeOptional

The type of packet capture. <code>Simple</code> captures sampled packets, and <code>full</code> captures entire payloads and non-sampled packets.

</summary>

One of the following:

const PCAPTypeSimple PCAPType = "simple"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

const PCAPTypeFull PCAPType = "full"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFull struct{…}

</summary>

ID stringOptional

The ID for the packet capture.

maxLength32

minLength32

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20id">Link to this property</a>

ByteLimit float64Optional

The maximum number of bytes to capture. This field only applies to <code>full</code> packet captures.

maximum1000000000

minimum1

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20byte_limit">Link to this property</a>

ColoName stringOptional

The name of the data center used for the packet capture. This can be a specific colo (ord02) or a multi-colo name (ORD). This field only applies to <code>full</code> packet captures.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20colo_name">Link to this property</a>

DestinationConf stringOptional

The full URI for the bucket. This field only applies to <code>full</code> packet captures.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20destination_conf">Link to this property</a>

ErrorMessage stringOptional

An error message that describes why the packet capture failed. This field only applies to <code>full</code> packet captures.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20error_message">Link to this property</a>

<details>

<summary>

FilterV1 <a href="https://developers.cloudflare.com/api/go/resources/magic_transit#(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)">PCAPFilter</a>Optional

The packet capture filter. When this field is empty, all packets are captured.

</summary>

DestinationAddress stringOptional

The destination IP address of the packet.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20filter_v1%20%2B%20(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)%20%3E%20(property)%20destination_address">Link to this property</a>

DestinationPort float64Optional

The destination port of the packet.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20filter_v1%20%2B%20(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)%20%3E%20(property)%20destination_port">Link to this property</a>

Protocol float64Optional

The protocol number of the packet.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20filter_v1%20%2B%20(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)%20%3E%20(property)%20protocol">Link to this property</a>

SourceAddress stringOptional

The source IP address of the packet.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20filter_v1%20%2B%20(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)%20%3E%20(property)%20source_address">Link to this property</a>

SourcePort float64Optional

The source port of the packet.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20filter_v1%20%2B%20(resource)%20magic_transit.pcaps%20%3E%20(model)%20pcap_filter%20%3E%20(schema)%20%3E%20(property)%20source_port">Link to this property</a>

</details>

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20filter_v1">Link to this property</a>

PacketsCaptured int64Optional

The number of packets captured.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20packets_captured">Link to this property</a>

<details>

<summary>

Status PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatusOptional

The status of the packet capture request.

</summary>

One of the following:

const PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatusUnknown PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatus = "unknown"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

const PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatusSuccess PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatus = "success"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

const PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatusPending PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatus = "pending"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

const PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatusRunning PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatus = "running"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20status%20%3E%20(member)%203">Link to this property</a>

const PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatusConversionPending PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatus = "conversion\_pending"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20status%20%3E%20(member)%204">Link to this property</a>

const PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatusConversionRunning PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatus = "conversion\_running"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20status%20%3E%20(member)%205">Link to this property</a>

const PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatusComplete PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatus = "complete"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20status%20%3E%20(member)%206">Link to this property</a>

const PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatusFailed PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullStatus = "failed"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20status%20%3E%20(member)%207">Link to this property</a>

</details>

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20status">Link to this property</a>

StopRequested TimeOptional

The RFC 3339 timestamp when stopping the packet capture was requested. This field only applies to <code>full</code> packet captures.

formatdate-time

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20stop_requested">Link to this property</a>

Submitted stringOptional

The RFC 3339 timestamp when the packet capture was created.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20submitted">Link to this property</a>

System PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullSystemOptional

The system used to collect packet captures.

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20system">Link to this property</a>

TimeLimit float64Optional

The packet capture duration in seconds.

maximum86400

minimum1

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20time_limit">Link to this property</a>

<details>

<summary>

Type PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullTypeOptional

The type of packet capture. <code>Simple</code> captures sampled packets, and <code>full</code> captures entire payloads and non-sampled packets.

</summary>

One of the following:

const PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullTypeSimple PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullType = "simple"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%3E%20(member)%200">Link to this property</a>

const PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullTypeFull PCAPListResponseMagicVisibilityPCAPsPCAPsResponseFullType = "full"

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201%20%3E%20(property)%20type">Link to this property</a>

</details>

<a href="#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)%20%3E%20(variant)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20magic_transit.pcaps%20%3E%20(model)%20PCAPListResponse%20%3E%20(schema)>)

### List packet capture requests

Go

HTTPTypeScriptPythonGoTerraform

```
package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/magic_transit"
  "github.com/cloudflare/cloudflare-go/option"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  page, err := client.MagicTransit.PCAPs.List(context.TODO(), magic_transit.PCAPListParams{
    AccountID: cloudflare.F("023e105f4ecef8ad9ca31a8372d0c353"),
  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", page)
}
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": [
    {
      "id": "66802ca5668e47a2b82c2e6746e45037",
      "filter_v1": {
        "destination_address": "1.2.3.4",
        "destination_port": 80,
        "protocol": 6,
        "source_address": "1.2.3.4",
        "source_port": 123
      },
      "offset_time": "2020-01-01T08:00:00Z",
      "status": "success",
      "submitted": "2020-01-01T08:00:00Z",
      "system": "magic-transit",
      "time_limit": 300,
      "type": "simple"
    }
  ],
  "success": true,
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": [
    {
      "id": "66802ca5668e47a2b82c2e6746e45037",
      "filter_v1": {
        "destination_address": "1.2.3.4",
        "destination_port": 80,
        "protocol": 6,
        "source_address": "1.2.3.4",
        "source_port": 123
      },
      "offset_time": "2020-01-01T08:00:00Z",
      "status": "success",
      "submitted": "2020-01-01T08:00:00Z",
      "system": "magic-transit",
      "time_limit": 300,
      "type": "simple"
    }
  ],
  "success": true,
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000
  }
}
```