tcpdump Documentation

A practical cheat sheet: capture basics, common filters, and everyday recipes.

BPF filters pcap CLI

Intro

tcpdump is a command-line packet analyzer using libpcap. You can capture live traffic, apply BPF filters, and save captures to .pcap for analysis in Wireshark.

Install & permissions

Debian / Ubuntu
sudo apt update
sudo apt install tcpdump
RHEL / CentOS
sudo yum install tcpdump
Fedora
sudo dnf install tcpdump
Capturing may require elevated privileges. Prefer running with the minimum permissions needed.

Capture basics

List interfaces
tcpdump -D
Basic capture on an interface
sudo tcpdump -i eth0
Capture N packets and stop
sudo tcpdump -i eth0 -c 50
Write to pcap
sudo tcpdump -i eth0 -w capture.pcap
Read a pcap file
tcpdump -r capture.pcap

Useful output options

Avoid name resolution
sudo tcpdump -i eth0 -nn
Faster and clearer: keeps IPs and numeric ports.
Show payload in ASCII
sudo tcpdump -i eth0 -A
Show payload in ASCII / hex
sudo tcpdump -i eth0 -X
More verbosity
sudo tcpdump -i eth0 -vvv
Full packets (no snaplen truncation)
sudo tcpdump -i eth0 -s 0 -w full.pcap
Increase capture buffer
sudo tcpdump -i eth0 -B 8192 -nn
Increases kernel capture buffer (KiB) to reduce packet drops.

Tcpdump Filter Builder

Leave empty for none.
Works for TCP/UDP mostly.
Kernel buffer in KiB.
Appended with AND if other filters exist.

sudo tcpdump -i eth0 -nn

Classic filters (BPF)

Filters go after the options: tcpdump [options] <filter>
IP Addresses
Traffic for a network (CIDR)
net 10.0.0.0/8
Traffic to or from a host
host 192.168.1.10
Traffic from host
src host 192.168.1.10
Traffic to host
dst host 192.168.1.10
Ports (TCP & UDP)
Traffic from or to a port
port 53
Traffic from a port
src port 443
Traffic to a port
dst port 22
Traffic for a range of ports
portrange 10000-20000
Protocols
TCP
tcp
UDP
udp
ICMP
icmp
ARP
arp
IPv6
ip6
Combine with AND / OR / NOT
DNS for a host
host 192.168.1.10 and udp port 53
SSH or RDP
tcp port 22 or tcp port 3389
Exclude a host
not host 10.0.0.5
Exclude a port
not port 3389
TCP flags (examples)
These are classic BPF flag expressions; they’re powerful but easy to mistype.
SYN packets only (often used to spot scans / new connections)
tcp[tcpflags] & tcp-syn != 0 and tcp[tcpflags] & tcp-ack == 0
RST packets
tcp[tcpflags] & tcp-rst != 0
FIN packets
tcp[tcpflags] & tcp-fin != 0
VLANs
VLAN
vlan
VLAN & IP
vlan and ip
Single VLAN
vlan 100

Common recipes

HTTP (cleartext)
sudo tcpdump -i eth0 -nn -A tcp port 80
DNS queries
sudo tcpdump -i eth0 -nn udp port 53
TLS / HTTPS endpoints
sudo tcpdump -i eth0 -nn tcp port 443
ICMP (ping / errors)
sudo tcpdump -i eth0 -nn icmp
Traffic to/from a single host + write pcap
sudo tcpdump -i eth0 -nn host 192.168.1.10 -w host_192.168.1.10.pcap

Performance note: -B capture buffer (kernel memory)

Recommended values

  • -B 4096 (4 MB) – light/medium traffic
  • -B 8192 (8 MB) – common default for busy links
  • -B 16384 (16 MB) – high-throughput / bursty traffic
Bigger buffers use more kernel memory. If you run many simultaneous captures, memory usage adds up.

Example command

Increase buffer + keep output readable
sudo tcpdump -i eth0 -nn -B 8192
Tip: combine with -w capture.pcap to avoid terminal overhead on heavy traffic.

How to confirm packet drops

tcpdump prints capture statistics when it stops (Ctrl+C). Look for: packets dropped by kernel

Example output
123456 packets captured
123789 packets received by filter
333 packets dropped by kernel

Linux limits (advanced)

Check current limits
sysctl net.core.rmem_max
sysctl net.core.rmem_default
Temporary increase (example)
# Example only: values depend on your environment
sudo sysctl -w net.core.rmem_max=33554432
sudo sysctl -w net.core.rmem_default=33554432
Use caution: changing sysctl values impacts the whole system.

Quick “high traffic” preset

Capture reliably for later analysis
sudo tcpdump -i eth0 -nn -s 0 -B 16384 -w capture.pcap

Tips & pitfalls

  • Use -nn while troubleshooting: name resolution can slow down and clutter output.
  • Use -s 0 when writing pcaps for later analysis (prevents truncated payloads).
  • Prefer writing to pcap for heavy debugging instead of printing everything to the terminal.
  • Be careful with -A on busy links: it can output a lot of data quickly.
We use cookies & process data
By using this site, you agree to our Terms and Privacy Policy. We process file uploads for network analysis only.