Want to see Kubeshark in action right now? Visit this live demo deployment of Kubeshark.
**Kubeshark** is an API traffic analyzer for Kubernetes, providing deep packet inspection with complete API and Kubernetes contexts, retaining cluster-wide L4 traffic (PCAP), and using minimal production compute resources.  Think [TCPDump](https://en.wikipedia.org/wiki/Tcpdump) and [Wireshark](https://www.wireshark.org/) reimagined for Kubernetes. Access cluster-wide PCAP traffic by pressing a single button, without the need to install `tcpdump` or manually copy files. Understand the traffic context in relation to the API and Kubernetes contexts. #### Service-Map w/Kubernetes Context  #### Export Cluster-Wide L4 Traffic (PCAP) Imagine having a cluster-wide [TCPDump](https://www.tcpdump.org/)-like capability—exporting a single [PCAP](https://www.ietf.org/archive/id/draft-gharris-opsawg-pcap-01.html) file that consolidates traffic from multiple nodes, all accessible with a single click. 1. Go to the **Snapshots** tab 2. Create a new snapshot 3. **Optionally** select the nodes (default: all nodes) 4. **Optionally** select the time frame (default: last one hour) 5. Press **Create**