tcpdump - dump traffic on a network
tcpdump是一个用于截取网络分组,并输出分组内容的工具。凭借强大的功能和灵活的截取策略,使其成为类UNIX系统下用于网络分析和问题排查的首选工具。
tcpdump捕获命令
# tcpdump -n -i ens192 ip proto \\icmp
tcpdump执行效果
[root@centos ~]# tcpdump -i ens192 ip proto \\icmp
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on ens192, link-type EN10MB (Ethernet), capture size 262144 bytes
11:11:35.431406 IP 10.10.10.1 > centos: ICMP echo request, id 14865, seq 167, length 64
11:11:35.431450 IP centos > 10.10.10.1: ICMP echo reply, id 14865, seq 167, length 64
11:11:36.435813 IP 10.10.10.1 > centos: ICMP echo request, id 14865, seq 168, length 64
11:11:36.435844 IP centos > 10.10.10.1: ICMP echo reply, id 14865, seq 168, length 64
11:11:37.445608 IP 10.10.10.1 > centos: ICMP echo request, id 14865, seq 169, length 64
11:11:37.445639 IP centos > 10.10.10.1: ICMP echo reply, id 14865, seq 169, length 64
11:11:38.444312 IP 10.10.10.1 > centos: ICMP echo request, id 14865, seq 170, length 64
11:11:38.444344 IP centos > 10.10.10.1: ICMP echo reply, id 14865, seq 170, length 64
11:11:39.568997 IP 10.10.10.1 > centos: ICMP echo request, id 22545, seq 0, length 64
11:11:39.569021 IP centos > 10.10.10.1: ICMP echo reply, id 22545, seq 0, length 64
11:11:40.573202 IP 10.10.10.1 > centos: ICMP echo request, id 22545, seq 1, length 64
11:11:40.573220 IP centos > 10.10.10.1: ICMP echo reply, id 22545, seq 1, length 64
11:11:42.580432 IP 10.10.10.1 > centos: ICMP echo request, id 22545, seq 3, length 64
11:11:42.580461 IP centos > 10.10.10.1: ICMP echo reply, id 22545, seq 3, length 64
11:11:43.585298 IP 10.10.10.1 > centos: ICMP echo request, id 22545, seq 4, length 64
11:11:43.585332 IP centos > 10.10.10.1: ICMP echo reply, id 22545, seq 4, length 64
11:11:44.587946 IP 10.10.10.1 > centos: ICMP echo request, id 22545, seq 5, length 64
11:11:44.587988 IP centos > 10.10.10.1: ICMP echo reply, id 22545, seq 5, length 64
11:11:45.590848 IP 10.10.10.1 > centos: ICMP echo request, id 22545, seq 6, length 64
11:11:45.590887 IP centos > 10.10.10.1: ICMP echo reply, id 22545, seq 6, length 64