How to create a TCP Dump capture for Wireshark on Linux

Home > Search > How-to
  by

At the bare minimum, the tcpdump command followed by the interface that you want to view the packets against is needed for the tcpdump command to display the packets in the console.

tcpdump -i eth0

 

The -v option produces verbose output, and the -w option writes the output to a file, instead of the console.

tcpdump -i eth0 -v -w capture.pcap 

 

The capture.pcap file(s) that will be created can become quite large (MB or even GB). For this reason, you need to first ensure the directory that will contain the capture.pcap file has plenty of available disk space. Use the df -h command to locate a directory that has plenty of available disk space, and then use the cd (change directory) command to move into the directory that has plenty of disk space.

df -h

 



Add a Comment




We will never share your name or email with anyone. Enter your email if you would like to be notified when we respond to your comment.




Please enter in the box below so that we can be sure you are a human.




Comments