This is our old Q&A Site. Please post any new questions and answers at


I am fairly new to Wireshark and need some help. In the past I have installed Wireshark on Windows, created a scheduled task, that ran a command similar to this: c:\Program Files\Wireshark>tshark -i 1 -a duration:3600 -w c:\WiresharkCapture\test

What this did was at a specified time, it would start a Wireshark scan and break it up into a bunch of files every so many minutes and then dump it into a folder.

This worked great. However, I am on a Linux (Debian) machine, and don't know how to go about creating the same type of results. Can someone please help?

Thank you.

asked 19 Apr '16, 10:34

darmstrong's gravatar image

accept rate: 0%

and don't know how to go about creating the same type of results.

You would do (almost) the same as on Windows, with the difference, that the scheduler on Linux is cron.

Please read that and then add a cron job with similar tshark parameters as shown in your question. You'll have to change the path to something Linux like (-w /var/tmp/test).


permanent link

answered 19 Apr '16, 13:29

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
accept rate: 15%

edited 19 Apr '16, 13:29

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 19 Apr '16, 10:34

question was seen: 1,945 times

last updated: 19 Apr '16, 13:29

p​o​w​e​r​e​d by O​S​Q​A