← Network reference library

Wolex engineer reference · Packet analysis

tcpdump & capture-filter quick reference

Capture a bounded, targeted conversation and read a saved trace without unnecessary name lookups.

Download branded PDF

Revision 2.0 · Documentation reviewed 2026-10-10 · Original Wolex reference

Choose interfaceCompile filterBound captureAnalyze saved file
Confirm interface and filter before capture. Packet count is not a wall-clock timeout; stop the capture at the end of the approved test window.

Quick reference

Option / filterPurposeWatch for
-DList capture interfacesNames vary by host
-nnKeep numeric addresses and portsAvoid lookup side effects
-i eth0Choose interfaceExample name; replace it
-c 200Stop after 200 matched packetsCan wait indefinitely on quiet flow
-s 128Limit bytes kept per packetMay truncate useful headers
-w flow.pcapWrite raw captureMay include sensitive content
-r flow.pcapRead saved captureNo new network capture
host / port / netlibpcap acquisition filterDifferent from Wireshark syntax

What to understand first

01

A capture filter runs during acquisition or reading; it can exclude packets permanently from the saved capture. Use parentheses and quote the expression to avoid shell interpretation.

02

Choose a snap length sufficient for the question. Header-limited capture reduces exposure but can lose encapsulated headers; -s 0 keeps full packets and may collect payloads.

03

Packet-count bounds do not stop a quiet capture on elapsed time. Plan an explicit operator stop or use an approved OS timeout mechanism with compatible syntax.

04

Capture-drop counters describe the collection path, not necessarily loss on the network. VLAN tags, tunnels and offload can change what a capture point sees.

Commands and interpretation

Inspection commands are read-only unless explicitly labeled otherwise. Capture commands start collection; configuration-mode commits change device state.

Interface and filter preparation

Read-only listing / compile check

tcpdump -D
tcpdump -i eth0 -d 'host 192.0.2.10 and tcp port 443'

Inspect: Listing and compiled-filter inspection do not save a trace. Confirm the chosen interface and intended match.

Targeted capture

Starts capture and writes a file

tcpdump -i eth0 -nn -s 128 -c 200 -w flow.pcap 'host 192.0.2.10 and tcp port 443'

Inspect: Use only authorized scope and required privileges. Stop when the test window ends; 128 bytes may be insufficient for encapsulated traffic.

Saved-file review

Reads existing file

tcpdump -nn -r flow.pcap 'tcp port 443'

Inspect: Read the saved flow numerically. Existing payload content remains in the file regardless of this display.

Worked example · Illustrative, not a device capture

Capture filters versus display filters

libpcap:   host 192.0.2.10 and tcp port 443
Wireshark: ip.addr == 192.0.2.10 && tcp.port == 443

The two expressions target a similar IPv4 conversation but belong to different filter languages.

Check matching packets against the capture link type; nested encapsulation can require additional filter treatment.

Troubleshooting sequence

  1. State the observation point, authorized endpoints, transport and time window.
  2. Select the real interface and validate the filter syntax before collection.
  3. Start the bounded capture, reproduce one attempt and stop deliberately.
  4. Review both directions and collection-drop counters before inferring network loss.
  5. Protect the trace and retain only the evidence needed for the troubleshooting question.

Common mistakes

  • Using an unbounded full-payload capture as the default.
  • Assuming -c provides a time limit or -nn hides captured data.
  • Missing the flow because the chosen interface sees a translated or encapsulated tuple.

Acceptance checks

  • Capture scope and duration match the approved test.
  • Relevant headers and both directions are available.
  • Trace storage and the escalation handoff preserve confidentiality.

Primary references

Vendor documentation and protocol specifications support this guide. The diagrams, scenarios and troubleshooting sequences are Wolex-authored.