tcpdump¶
Command-line packet capture — the tool that works when nothing else does
- Version recorded: 4.99.5
- Categories:
capture-analysis,workstation - Upstream: https://www.tcpdump.org/
What it does¶
Captures network traffic from an interface and prints or saves it, with a filter language for selecting what to record.
Why you would want it¶
It is present on everything, needs no display, and its capture files are read by every other tool including Wireshark. On a headless field machine or over a slow SSH link it is the only practical option.
Before it will work¶
Root, or the CAP_NET_RAW capability, to open an interface for capture.
How it installs¶
- apt:
tcpdump
Known problems¶
Capturing to a terminal on a busy interface produces more output than anyone can read; -w to a file and analyse afterwards. Its filter syntax is not Wireshark's display-filter syntax, which catches people out constantly.
Keeping it current¶
- probe: apt policy
- strategy: apt_upgrade
Source: catalog/packages/tcpdump.yaml