pktmon filter remove# Remove All Filterspktmon filter list# List all Filterspktmon filter add -I 100.100.100.0/24# Capture the traffic for Specified IPpktmon filter add -p 53 -I 100.100.100.0/16 101.101.101.0/16# filter IP and Port
pktmon start --etw --pkt-size 0 --comp 1
pktmon start -c --comp nics -m real-time # Capture Real time
pktmon stop
#Create Directory where you want to store pcap
mkdir C:\Temp1 # Create Directory where you want to store pcap
#Convert etltp log.pcapng for wireshark
pktmon etl2pcap C:\WINDOWS\system32\PktMon.etl -o C:\Temp1\log.pcapng