

The most powerful display filter in the industry.The captured network data can be browsed through the GUI or through the TTY mode TShark utility.Multi-platform: runs on Windows, Linux, macOS, Solaris, FreeBSD, NetBSD and many other platforms.In-depth inspection of hundreds of protocols, and more protocols are being added all the time.-w − write the output to the file mycapture identifier.-b files: − the number of files to capture before overwriting the oldest.-b filesize: − file size in kB before starting a new.-i − interface number (listed from dumpcap -D).# dumpcap -i 1 -b filesize:100000 -b files:20 -w mycapture.pcapng pcap files of 100MB each, replacing the oldest file with the twenty-first file and so on… This allows a continuous capture without exhausting disk space. The following example will provide a ringbuffer capture.


To see all dumpcap options, use the -h flag. Used in combination with tmux will allow the capture of packets in a detached session. Tcp.port=80||tcp.port=3306||tcp.port=443ĭumpcap is part of Wireshark and can be used for capturing packets without the GUI. This will filter traffic within any of the private network spaces.

To only see LAN traffic and no internet traffic, run
