Skip to content

tcpdump

Command-line packet capture — the tool that works when nothing else does

What it does

Captures network traffic from an interface and prints or saves it, with a filter language for selecting what to record.

Why you would want it

It is present on everything, needs no display, and its capture files are read by every other tool including Wireshark. On a headless field machine or over a slow SSH link it is the only practical option.

Before it will work

Root, or the CAP_NET_RAW capability, to open an interface for capture.

How it installs

  • apt: tcpdump

Known problems

Capturing to a terminal on a busy interface produces more output than anyone can read; -w to a file and analyse afterwards. Its filter syntax is not Wireshark's display-filter syntax, which catches people out constantly.

Keeping it current

  • probe: apt policy
  • strategy: apt_upgrade

Source: catalog/packages/tcpdump.yaml