-D
-i interface
-i interface -w outfile
-r infile
# read only N packets
-r infile -c N
# hex only
-xx
# hex and ascii
-XX
--number
-#
-e
-ttt # delta between frames
-tttt # date
-ttttt # delta since frame 1
# flush on end of line
-l
# flush on end of packet
- U
tcpdump -i interface -l | grep --line-buffered expr
tcpdump -i interface -l | grep --line-buffered expr | awk '{print $3}'
tcpdump -i interface -l | grep --line-buffered expr | awk '{print $3; fflush()}' | python3 decode.py
man pcap-filter
tcpdump -r infile 'expr_string'
tcpdump -r infile -F expr_file
'ether[0x30] == 0x63'
'ether[0x30:2] == 0x6368'
'len == 58'
'len != 58'
0 2 4 6 8 A C E
0x0000: 0001 0203 0405 0607 0809 0a0b 0c0d 0e0f
0x0010: 1011 1213 1415 1617 1819 1a1b 1c1d 1e1f
0x0020: 2021 2223 2425 2627 2829 2a2b 2c2d 2e2f
0x0030: 3031 3233 3435 3637 3839 3a3b 3c3d 3e3f