Determine interface
tcpdump -D
Capture and Display Top Conversations
tcpdump -i eth1 -tnn -c 20000 | awk -F " " '{print $2" "$3" "$4}' | sort | uniq -c | sort -nr | more
Read a file
tcpdump -qns 0 -A -r file.pcap
Command to allow tcpdump/dumpcap to execute as any user instead of root:
chmod u+s /usr/bin/dumpcap
Restrictive method:
groupadd netcapture
usermod -a -G netcapture _username_
chgrp netcapture /usr/sbin/dumpcap
chgrp netcapture /usr/sbin/tshark
chmod 750 /usr/sbin/dumpcap
chmod 750 /usr/sbin/tshark
setcap cap_net_raw,cap_net_admin=eip /usr/sbin/dumpcap
setcap cap_net_raw,cap_net_admin=eip /usr/sbin/tshark