netsh does not give you a live readout in the terminal like tcpdump does. Instead, it saves the output as an .etl (Event Trace Log) file. While you can convert these, most network admins prefer to open the resulting file in (now deprecated) or, more commonly, Wireshark .