Concept and mechanism
A cumulative counter needs time context. If input errors rise from one hundred twenty to one hundred forty-five during rehearsal, twenty-five new events were counted within that interval. This does not mean twenty-five percent loss or demonstrate error cause. Compare traffic, symptoms, and physical state. Tools also have scope: monitor traffic observes packets received and sent by the Routing Engine rather than providing universal transit capture. An empty view can reflect observation placement. Choose a mechanism representing the flow and confirm platform and release limitations.
Guided application
In a fictional incident, capture is empty while the application confirms some deliveries. Correlate evidence before restarting the router because partial activity and a possible observation gap exist. For maintenance, prepare package, platform, upgrade path, compatibility, and recovery. Failed validation deserves investigation; no-validate should not be an automatic reaction. Procedures vary, including on VM Host platforms, and need specific documentation. Confirm time too: configuring an NTP server does not prove synchronization. Check associations and operational state before comparing timestamps across systems. Handover should retain intervals, commands, limits, and success criteria. Credential recovery and shutdown require authorized device-appropriate procedures; these initial exercises do not replace a lab for those operations.
120 → 145 means 25 additional events in the interval without alone proving a cause.
Common pitfalls
Cumulative count as rate; partial capture as total loss; automatic no-validate; configured NTP as synchronized.
Related topics: Addressing and capacity · Junos planes and state interpretation · CLI, candidate, and rollback
Document what you measured and measurement limits.
Reference: Routing Engine packet monitoring · JN0-106, effective 2026-04-06; Junos OS 21.2 exam baseline