This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I am attempting to capture packets, gzip and overwritten oldest file when about to run of disk space:

tcpdump -ni eth0 -G 180 -w 'trace_%Y-%m-%d_%H:%M:%S.pcap' -z gzip

The one liner is capturing packets and zipping them but I am unable to setup a script to overwriting part.

asked 09 Sep '14, 13:04

ksudi's gravatar image

ksudi
11113
accept rate: 0%


You should look into using dumpcap i.s.o. tcpdump. It's the capture engine {wire|t}shark uses to capture network traffic and write it to disk. It has multiple capture file option (-b) which can cycle files based on time, size and number of files.

permanent link

answered 10 Sep '14, 03:50

Jaap's gravatar image

Jaap ♦
11.7k16101
accept rate: 14%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×19
×11
×1

question asked: 09 Sep '14, 13:04

question was seen: 1,662 times

last updated: 10 Sep '14, 03:50

p​o​w​e​r​e​d by O​S​Q​A