Skip to content

tcpdump

Command-line packet capture and filter reader

VerifiedNetworking· Traffic AnalysisBeginnerBSD-3-ClauseOpen sourceEntry revised 11 Jan 2026
  • Linux
  • macOS
  • Windows
  • Kali
  • Parrot
  • Arch
  • Fedora
  • Docker
This entry is thinner than the rest of the directory — missing sections are shown as such rather than filled with filler.Improve this pageContribute

Overview

4 commands documented

tcpdump captures packets through libpcap and prints decoded summaries. It is what you use on a headless server, inside a container, or whenever you want a capture file you can hand to Wireshark.

The BPF expressions it accepts are the same ones Wireshark uses for capture filters, which makes it the natural place to learn filtering: small, explicit, no GUI.

Supported platforms

8

Documented install or usage guidance

Learning curve

beginner

Difficulty of becoming productive, not of the underlying theory

Tags

capture, pcap, bpf, diagnostics, server

Dataset entry

tcpdump.ts

Reviewed 2026-01-11

Installation

Grouped by platform. Elevation requirements are marked per method.

Windows build + Npcap

ManualnpcapOfficial

Use the winpcap/npcap-based build from the official download page.

Open official source

Package availability follows your distribution and enabled repositories. Entry revised 11 Jan 2026 — confirm the current release on the project's own download page.

Commands

4 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Watch one host and port

bash

The default diagnostic: readable output, no DNS or name lookups so nothing hangs.

sudo tcpdump -nn -i any host 192.0.2.10 and port 443

Notes

  • `-nn` skips name and port resolution; add `-vv` for more detail, `-A` to print packet payloads as ASCII.

02Capture to a file with a size cap

bash

Ring-buffered capture that cannot fill the disk during a long-lived investigation.

sudo tcpdump -i eth0 -w /tmp/edge.pcap -C 50 -W 5 'port 53 or port 443'

Notes

  • `-C 50` rotates at 50 MB, `-W 5` keeps five files. Read them back with `-r` or open in Wireshark.

03Filter a saved capture

bash

Re-reads a file with an expression applied at read time, which is how you isolate one TCP stream.

sudo tcpdump -nn -r /tmp/edge.pcap 'tcp[tcpflags] & (tcp-syn|tcp-rst) != 0'

04Bound and summarise a test

bash

Captures a fixed number of packets and prints interface statistics on exit.

sudo tcpdump -nn -i eth0 -c 200 -e

Notes

  • `-e` includes link-layer addresses, which you need when reasoning about ARP or a bridge.

What it is used for

  • Service-to-service reachability

    Prove whether packets arrive at all before blaming the application.

  • DNS and TLS troubleshooting

    Look at query names, response codes and handshake failures.

  • Evidence collection

    Bounded captures as an attachment to an incident record.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

"tcpdump: eth0: No such device exists"Cause 1/3

Possible causes

  • Interface renamed by predictable naming, or you are inside a container with its own namespace.

Usual fix

List devices with `tcpdump -D` or `ip -br link`, and capture inside the correct namespace (`nsenter -n -t <pid>`).

Capture file is empty although the command ranCause 2/3

Possible causes

  • Filter expression matched nothing (a common typo is `port:443` instead of `port 443`).

Usual fix

Remove the filter and retest; build expressions up one term at a time.

Payloads print as `IP (frag ...)` or gibberishCause 3/3

Possible causes

  • Segmentation offload, or truncated snapshot length.

Usual fix

Capture with `-s 0` on the interface under test, and remember that encrypted payload stays encrypted.

Tips

  • Write to a file and analyse afterwards: reading a bounded capture is far kinder to a production link than printing every packet.
  • Quote your filter expression — an unquoted `or` gets interpreted by the shell.
  • `-Q in` / `-Q out` separates directions when a device is doing NAT.

Alternatives & comparisons

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Networking

Looking for alternatives?

Wireshark cover adjacent parts of the same job.

Compare side by side