Knowledge Base

tcpdump cheat sheet: filters, options and common captures

tcpdump captures packets from a network interface and prints or saves them. This page is a working reference for the options and filter expressions that come up most often: selecting an interface, narrowing to a host or port, matching TCP flags, and writing capture files you can open later in Wireshark.

Live capture requires root, so the commands below are normally run under sudo.

The basic form

tcpdump -i en0
tcpdump -i any
tcpdump -D            # list the interfaces available

Two options are worth adding almost every time. The -n option stops tcpdump resolving addresses and ports to names, which matters because those lookups generate their own traffic and will appear in your capture. The -c option stops after a set number of packets, which keeps an exploratory command from filling the terminal.

tcpdump -i en0 -n -c 100

Filtering by host, network and port

Filter expressions use Berkeley Packet Filter syntax. Direction qualifiers (src, dst) and type qualifiers (host, net, port) combine freely.

tcpdump host 10.0.0.1
tcpdump src host 10.0.0.1
tcpdump net 10.0.0.0/24
tcpdump port 443
tcpdump portrange 8000-8100
tcpdump udp port 53

Combine them with and, or and not. Quote the whole expression when it contains parentheses or pipes, otherwise the shell will try to interpret them.

tcpdump 'tcp port 80 and host 10.0.0.1'
tcpdump 'not arp and not icmp'

Protocol and flag filters

Byte-offset expressions reach into the headers directly. These are the ones worth memorising: the first catches connection setup and teardown, the second isolates resets, and the third finds packets larger than a given size.

tcpdump 'tcp[tcpflags] & (tcp-syn|tcp-fin) != 0'
tcpdump 'tcp[tcpflags] & tcp-rst != 0'
tcpdump 'ip[2:2] > 1400'
tcpdump 'less 128'
tcpdump vlan
tcpdump ether broadcast

Writing and reading capture files

Writing to a file rather than the terminal preserves the full packets and lets you analyse them later in Wireshark or tshark. Filters can be applied again on read, so capture broadly and narrow afterwards.

tcpdump -i en0 -w capture.pcap
tcpdump -r capture.pcap
tcpdump -r capture.pcap 'port 443'

For anything long-running, rotate the files. -C sets a size in millions of bytes, -W caps how many are kept, and -G rotates on a time interval using strftime placeholders in the name.

tcpdump -i en0 -C 100 -W 10 -w capture.pcap
tcpdump -i en0 -G 3600 -w cap-%Y%m%d-%H%M%S.pcap

Options worth remembering

-i   interface to capture from, or any
-n   do not resolve names (and do not generate lookup traffic)
-c   stop after N packets
-w   write raw packets to a file
-r   read from a file instead of an interface
-e   include the link-layer header
-A   print payload as ASCII
-X   print payload as hex and ASCII
-tttt print a full human-readable timestamp
-s   snaplen; modern builds default to the full packet, so this is
     rarely needed except to deliberately truncate
-Q   capture direction: in, out or inout

From ad hoc capture to continuous capture

tcpdump is the right tool for a question you are asking now, on one interface, about traffic that is still flowing. It is the wrong tool for a question you will ask next week about traffic that has already passed, because by then nothing was recorded.

That gap is what continuous capture addresses: recording every packet across many links so the evidence exists before anyone knows which question matters. See what PCAP is for the file format and its trade-offs, and Corvil Network Capture for capture at line rate with nanosecond timestamps in trading environments.