Capture traffic to or from one host
Build a paste-ready command, then review its compatibility and effects before running it.
tcpdump -ni <interface> -c 20 host <address>Complete required fields to copy the generated command.
read-onlyno known side effects Compatibility
LinuxVerified for Linux using posix, bash, zsh syntax.
Operational knowledgereview due 2027-01-20
Requirementstcpdumptcpdump must be installed and available on PATH.
Version supporttcpdump Current supported releasesVerified for linux using posix, bash, zsh syntax; consult compatibility notes for platform-specific differences.
Expected signals12:14:12.110210 IP 192.0.2.20.44118 > 192.0.2.10.443: Flags [P.], seq 1:518, ack 1, win 501, length 517Representative successful output; values vary with the selected target and system state.
Known errorstcpdump: command not foundtcpdump is missing or is not available on PATH.
Verifytcpdump -ni {{interface}} -c 20 host {{address}}The output matches the expected target and exits without an error.Rollback noteNot required: this command is read-only and does not change system state.
Command breakdown
01tcpdumpCommandRuns the tcpdump stage of this one-liner.
02-niOptionConfigures tcpdump with the -ni option.
03<interface>ParameterA value supplied in the Fill parameters section.
04-cOptionConfigures tcpdump with the -c option.
0520ArgumentPasses 20 to tcpdump.
06hostArgumentPasses host to tcpdump.
07<address>ParameterA value supplied in the Fill parameters section.
Example input
tcpdump -ni eth0 -c 20 host 192.0.2.10
Example output
12:14:12.110210 IP 192.0.2.20.44118 > 192.0.2.10.443: Flags [P.], seq 1:518, ack 1, win 501, length 517
Illustrative output — exact values vary by system and data.
Official sources