Wednesday, 12 June 2013

Script to run packet captures.

cat tshark.sh
####################################
n=10
tshark -i 2 -w db1_shark_10min.pcap &
pid=$!
at now + $n minutes <<<"kill -HUP $pid"
####################################

execute script
sh tshark.sh > cap1

This script captures wireshark understandable packet every 10 minutes.