Aug 14, 2012

Monitoring network traffic using tcpdump

tcpdump is an excellent tool for monitoring network traffic.

Below are few examples that illustrate capturing of traffic from a specific IP
(Note: unless specifically configured to do otherwise, tcpdump needs to be run as root)

For a summarized output :
tcpdump -nvvS src 10.24.24.121

For a detailed output :
tcpdump -nvvXSs 1514 src 10.24.24.121

Detailed output with packet capture:
tcpdump -nvvXSs 1514 src 10.24.24.121 -w /tmp/abc.pcap

-n => Print IP addresses as is (without resolving to hostnames)
-w /tmp/abc.pcap => write captured packets to file
-vv => extra verbose
-X => print data in packets in hex and ASCII
-s => snapshot length
-S => prints absolute TCP sequence number

This .pcap file can then be opened up in wireshark for further analysis.