yum -y install tcpdump
yum install wireshark -y
列出可用网卡
tshark -D
tcpdump
tcpdump -nn udp dst port 1947 and src 192.168.100.101
tcpdump -i eth0 tcp port not 22 -C 2048 -w /tmp/包名字
固定方向
tcpdump -nn tcp and dst host 172.16.100.3 and src host 172.16.100.4 and dst port 80 and src port 60001
tshark
-i 网卡序号
./tshark -i 5 -n -f 'tcp dst port 80' -Y 'http.request.uri'