tcpdump and tshark: Packet Capture in CLI
When debugging network issues in Linux infrastructure, ping and curl are not enough. Sometimes you need to see what is actually traveling over the wire. tcpdump is the standard tool for capturing packets from the CLI. tshark is its sibling from the Wireshark suite, convenient for scripting.
Quick Start with tcpdump
Check that packets are reaching the host:
The utility puts the interface into promiscuous mode and prints one line per packet passing through. By default it works with the first interface it finds, but specifying explicitly is better.
For a quick test without DNS resolution (to avoid timeout when there is no network):
-nn prevents resolving both hostnames and ports.
Key Flags
| Flag | Purpose |
|---|---|
-i iface | Interface |
-c N | Capture N packets and exit |
-n | Do not resolve hostnames |
-nn | Do not resolve hostnames and ports |
-v, -vv, -vvv | Increase output verbosity |
-w file | Write raw dump to file (pcap) |
-r file | Read dump from file |
-X | Show hex + ASCII packet body |
-s N | Truncate each packet to N bytes (0 = full) |
-C | Rotate output file when it reaches N MB |
The -v flags are useful for debugging: the first level shows TTL and ID, the second shows flags and window size, the third adds ACK and displays the full IP header.
BPF Filters
tcpdump uses Berkeley Packet Filter. The syntax reads left to right.
Filters combine with and, or, not. Quotes are needed when the expression contains spaces or special characters.
Do not run tcpdump -i any in production without restricting by host or port. You will get a flood of traffic and waste disk space for no reason.
Writing to File and Reading
Capturing to a file is mandatory practice. A live sniffer dumps data dozens of lines per second; analyzing in the terminal is impossible.
The pcap format is binary. The -C option limits file size:
This creates files /tmp/capture-0, /tmp/capture-1 … up to 5 files, each up to 10 MB. -W sets the number of files.
tshark as a tty-free Alternative
tshark is the command-line part of Wireshark. It produces structured output convenient for parsing in scripts:
-T fields -e extracts specific fields from each packet:
Reading pcap files with tshark is more convenient than with tcpdump:
tshark does not support -C rotation like tcpdump, but it handles live filters better (full Wireshark dissector engine).
Reading Dumps in Wireshark
A pcap created by tcpdump opens in Wireshark without conversion:
In Wireshark Apply as display filter you enter the same BPF syntax: tcp.port == 443 && ip.src == 10.0.0.1.
If the file is large (>100 MB), do not open it entirely. Use tcpdump -r with a pre-filter to extract the needed slice: tcpdump -r big.pcap -nn 'host 10.0.0.5' -w small.pcap.
Common Mistakes
- Forgot
-c— the process hangs, capturing traffic indefinitely. Add the limit immediately. - No permissions — you need root or
sudo tcpdump. In modern distributions you can grant capabilities:setcap cap_net_raw,cap_net_admin=eip /usr/sbin/tcpdump. -wdoes not work with-l(line-buffering) simultaneously. If you need progress — write to file and read in parallel viatail -f.- File was written but reads empty — possibly there was no traffic matching the filter. Check
tcpdump -i eth0 -nnwithout a filter.