Capture ten TCP SYN packets on an interface
Build a paste-ready command, then review its compatibility and effects before running it.
tcpdump -ni <interface> -c 10 'tcp[tcpflags] & tcp-syn != 0'Complete required fields to copy the generated command.
read-onlyno known side effects Compatibility
LinuxVerified for Linux using posix, bash, zsh syntax.
Operational knowledgereview due 2027-01-20
Requirementstcpdumptcpdump must be installed and available on PATH.
Version supporttcpdump Current supported releasesVerified for linux using posix, bash, zsh syntax; consult compatibility notes for platform-specific differences.
Expected signals12:14:03.101842 IP 198.51.100.7.53422 > 192.0.2.10.443: Flags [S], seq 1001, win 64240, length 0Representative successful output; values vary with the selected target and system state.
Known errorstcpdump: command not foundtcpdump is missing or is not available on PATH.
Verifytcpdump -ni {{interface}} -c 10 'tcp[tcpflags] & tcp-syn != 0'The output matches the expected target and exits without an error.Rollback noteNot required: this command is read-only and does not change system state.
Command breakdown
01tcpdumpCommandRuns the tcpdump stage of this one-liner.
02-niOptionConfigures tcpdump with the -ni option.
03<interface>ParameterA value supplied in the Fill parameters section.
04-cOptionConfigures tcpdump with the -c option.
0510ArgumentPasses 10 to tcpdump.
06'tcp[tcpflags] & tcp-syn != 0'ArgumentPasses 'tcp[tcpflags] & tcp-syn != 0' to tcpdump.
Example input
tcpdump -ni eth0 -c 10 'tcp[tcpflags] & tcp-syn != 0'
Example output
12:14:03.101842 IP 198.51.100.7.53422 > 192.0.2.10.443: Flags [S], seq 1001, win 64240, length 0
Illustrative output — exact values vary by system and data.
Official sources