
tcpdump
tcpdump not port 22
tcpdump not port 143 and not port 25 and not port 22
tcpdump port 143
tcpdump host hal9000
tcpdump -i eth1
tcpdump udp
tcpdump -l | tee tcpdump_`date +%Y%m%e-%k.%M`
tcpdump -w tcpdump_raw_`date +%Y%m%e-%k.%M`
tcpdump -r tcpdump_raw_YYYMMDD-H.M
tcpdump port 32772 -w dump_32772
17:26:22.924493 IP www.linux.org.www > test.linux.org.34365: P 2845:3739(894) ack 1624 win 9648 <nop,nop,timestamp 326501459 24374272>
18:12:45.149977 IP www.linux.org.www > test.linux.org.34536: . 1:1449(1448)