sngrep is a terminal tool that captures SIP traffic and draws each call as a ladder diagram, which makes most VoIP faults visible in seconds: who sent what, which response failed, which codecs were offered, and which addresses each side asked to receive audio on. This guide covers installing it, capturing and reading a call, saving a capture to share, checking the RTP audio, and the Asterisk logger as an alternative when sngrep is not available.
Short answer: Install sngrep (apt install sngrep, or from EPEL on AlmaLinux and Rocky), run sngrep -d any port 5060, make a test call, select it and press Enter for the ladder. Press F2 to save it as a pcap or text file. If audio is the problem, check the c= and m=audio lines in each SDP: a private address in the PBX’s offer to the provider means one-way audio.
Table of Contents
Install sngrep
# Debian / Ubuntu
apt install sngrep
# AlmaLinux / Rocky 8-10
dnf install epel-release
dnf install sngrep
sngrep -V
sngrep needs root (or the capture capability) to read packets. It does not change anything on the server, so it is safe on a live PBX.
Capture and read a call
sngrep -d any port 5060 # all interfaces, SIP on 5060
sngrep -c -d any port 5060 # only calls (INVITE dialogs), hide OPTIONS and REGISTER
The first screen lists dialogs as they happen. Make the test call, highlight it with the arrow keys and press Enter. The ladder shows each host as a column and each SIP message as an arrow. Press Enter on a message to see it in full, and F6 for the raw text. Things to look for:
- The final response: the first 4xx, 5xx or 6xx is the reason the call failed. Look it up in the SIP response codes tool.
- Repeated arrows: the same INVITE or 200 OK sent again and again means the other side is not receiving it or its reply is lost.
- Missing ACK: a 200 OK with no ACK after it ends in a BYE about 32 seconds later.
- SDP: the
c=line is where that side wants audio sent, andm=audiogives the port and codecs.
Filter, save and share a capture
Press F7 to filter by number, method or address, and Space to select several dialogs. F2 saves the selection as a pcap (for Wireshark) or plain text. You can also capture straight to a file on a busy server and read it later:
sngrep -d any -O /root/sip-$(date +%F).pcap port 5060 # capture to a file
sngrep -I /root/sip-2026-10-03.pcap # read it back
The text export pastes straight into our SIP trace analyzer, which lists NAT, codec and timer problems for you. Replace phone numbers and remove any Authorization headers before you send a capture to anyone else.
Check the audio (RTP)
SIP sets up the call, RTP carries the voice. When signalling looks right but there is no audio, check whether RTP packets are flowing in both directions:
# RTP between the PBX and the provider's media address (from the SDP)
tcpdump -ni any udp portrange 10000-20000 and host 203.0.113.30 -c 50
# or from the Asterisk CLI during a call
rtp set debug ip 203.0.113.30
rtp set debug off
Packets in only one direction mean a firewall or NAT problem on the side that is not receiving: check that the RTP range is open and that the PBX advertises its public IP. sngrep can also record RTP with sngrep -r, and Wireshark’s Telephony, VoIP Calls menu can play the audio from a pcap.
Use the Asterisk logger instead
When you cannot install packages, Asterisk’s own logger prints every SIP message it sends and receives to the CLI:
asterisk -rvvv
pjsip set logger host 203.0.113.20
# make the call
pjsip set logger off
The logger sees messages after Asterisk has decrypted TLS, which sngrep cannot, but it only shows Asterisk’s view: if a router or SIP ALG changes packets on the way, compare with a capture taken outside the PBX.
Troubleshooting SIP with sngrep at a glance



Official documentation: sngrep, tcpdump manual, Asterisk documentation, Wireshark VoIP calls.
Related: SIP trace analyzer · SIP error codes · Fix one-way audio · Disable SIP ALG.
Frequently asked questions
Can sngrep see SIP over TLS?
Not the content. With TLS on port 5061 the packets are encrypted, so use the Asterisk pjsip logger, which shows the decrypted messages, or test with UDP temporarily.
Is it safe to run sngrep on a production PBX?
Yes. It only reads packets and does not change the system. On a very busy server, filter by port or host and use -c to limit memory use, or capture to a file with -O.
Why does sngrep show nothing?
Run it as root, choose the right interface (-d any), and check the port: providers often use 5060 but some use 5080 or another port, and TLS on 5061 shows encrypted packets only.
How do I capture a call that happens at random times?
Capture to a rotating file with sngrep -O or tcpdump -C/-W, then open it with sngrep -I when the fault is reported.