Start capture.
pcapdump -stop [<interface(s)>]
Stop capture.
pcapdump -status
Show capture status.
pcapdump -show [<interface(s)>] [-num={ALL | <Integer>}]
Show a captured packets brief.
pcapdump -write [<interface(s)>] [-filename=<String>]
Write the captured packets to disk.
pcapdump -wipe
Remove all captured packets from memory.
pcapdump -cleanup
Remove all captured packets, release capture mode and delete all written capture files from disk.
Options
-cleanup Remove all captured packets, release capture
mode and delete all written capture files from disk.
-count=<value> Number of packets to capture.
-destport=<0...65535> Destination TCP/UDP port filter.
-eth=<Ethernet Address> Ethernet address filter.
-ethdest=<Ethernet Address> Ethernet destination address filter.
-ethsrc=<Ethernet Address> Ethernet source address filter.
-filename=<String> Filename for capture file.
-icmp ICMP filter.
-ip=<IP4 Address> IP address filter.
-ipdest=<IP4 Address> Destination IP address filter.
-ipsrc=<IP4 Address> Source IP address filter.
-ipversion=<1...15> IP version filter.
-num={ALL | <Integer>} Maximum number of entries to show (default: 20).
-out Realtime packet brief dumped to console.
-out-nocap Unbuffered (not stored in memory) realtime packet
brief dumped to console.
-port=<0...65535> TCP/UDP port filter.
-promisc Set iface in promiscuous mode.
Chapter 2: Command Reference
72