paperlined.org
apps > tcpdump
document updated a month ago, on Apr 10, 2025

the basic starting place for a tcpdump command

sudo tcpdump --interface=any --snapshot-length=0 -n -w /var/tmp/$HOSTNAME.$(date +%4Y-%m-%d_%H-%M-%S).pid_$$.pcap;   ls -lrt /var/tmp/*.pcap | tail
An explanation of each flag:

alternatively:

PCAPFILE=/var/tmp/$HOSTNAME.$$.pcap;   rm -f "$PCAPFILE";   tcpdump --interface=any --snapshot-length=0 -n -w "$PCAPFILE"

And consider adding some filter onto the end: