dumpcap
TLDR
Capture on default interface
SYNOPSIS
dumpcap [options]
DESCRIPTION
dumpcap is a network traffic capture tool from the Wireshark project. It captures packets and writes them to files in pcapng or pcap format. Unlike Wireshark or tshark, dumpcap focuses solely on capture without protocol dissection.
The tool is designed for minimal resource usage and long-running captures. It supports ring buffers for continuous capture with automatic file rotation, making it suitable for network monitoring.
PARAMETERS
-i interface
Interface to capture on.-w file
Output file name.-D
List available interfaces.-c count
Stop after capturing count packets.-a condition
Stop condition: duration, filesize, files.-b option
Ring buffer option: filesize, duration, files.-f filter
Capture filter (BPF syntax).-p
Don't capture in promiscuous mode.-s snaplen
Packet snapshot length.-q
Quiet mode; less output.
RING BUFFER EXAMPLE
dumpcap -i eth0 -b filesize:100000 -b files:10 -w capture.pcapng
CAVEATS
Requires root or CAPNETRAW capability. Capture files can grow large quickly. Ring buffer helps manage disk space. No packet analysis; use tshark or Wireshark for dissection. Performance is better than tshark for high-speed capture.
HISTORY
dumpcap is part of the Wireshark project, originally Ethereal, created by Gerald Combs in 1998. It was separated from the main application to provide a dedicated capture engine that could run with elevated privileges while analysis runs unprivileged.


