<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Tshark on Lead DevOps</title><link>https://lead-devops.blackdevhub.online/en/tags/tshark/</link><description>Recent content in Tshark on Lead DevOps</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Thu, 03 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://lead-devops.blackdevhub.online/en/tags/tshark/index.xml" rel="self" type="application/rss+xml"/><item><title>tcpdump and tshark: Packet Capture in CLI</title><link>https://lead-devops.blackdevhub.online/en/posts/tcpdump-tshark-cli-packet-capture/</link><pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/tcpdump-tshark-cli-packet-capture/</guid><description>&lt;p&gt;When debugging network issues in Linux infrastructure, &lt;code&gt;ping&lt;/code&gt; and &lt;code&gt;curl&lt;/code&gt; are not enough. Sometimes you need to see what is actually traveling over the wire. tcpdump is the standard tool for capturing packets from the CLI. tshark is its sibling from the Wireshark suite, convenient for scripting.&lt;/p&gt;&#10;&lt;h2 id="quick-start-with-tcpdump"&gt;Quick Start with tcpdump&#10;&lt;/h2&gt;&#10;&lt;p&gt;Check that packets are reaching the host:&lt;/p&gt;&#10;&lt;div class="td-code td-code--untitled" id="td-code-4d81bd54-fence-0" data-td-code data-td-code-auto-id&#10; data-td-language="bash" data-td-line-count="1"&gt;&#10; &lt;div class="td-code__viewport" id="td-code-4d81bd54-fence-0-viewport" data-td-code-viewport&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;tcpdump -i eth0 host 10.0.0.5&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#10;&lt;/div&gt;&#10;&lt;p&gt;The utility puts the interface into promiscuous mode and prints one line per packet passing through. By default it works with the first interface it finds, but specifying explicitly is better.&lt;/p&gt;</description></item></channel></rss>