Quick Basics

Find interfaces

tcpdump -D

Start a full-packet capture (rotate every 5 min, keep 3 files)

sudo tcpdump -i eth0 -s 0 -nn -w cap_%Y%m%d_%H%M%S.pcap -G 300 -W 3

Read a capture

tcpdump -nn -tttt -r cap_*.pcap | head