如何合并服务器两个网卡Eth0、Eth1的tcpdump抓包文件?
Hey Luke, nice to help you out with this! Here's a straightforward, step-by-step way to capture traffic on both eth0 and eth1, then merge the captures into a single file:
You’ll need to run tcpdump for each interface at the same time to ensure timestamps stay aligned. You can do this in two separate terminal windows, or background the processes if you prefer:
For eth0, save captures to
eth0_capture.pcap:sudo tcpdump -i eth0 -w eth0_capture.pcap -UThe
-Uflag makestcpdumpwrite packets to the file in real-time (useful if you want to merge before stopping the capture, though it’s optional for one-off captures).For eth1, save captures to
eth1_capture.pcap:sudo tcpdump -i eth1 -w eth1_capture.pcap -U
If you want to run these in the background (so you don’t need two terminals), use nohup to keep them running even if you log out:
nohup sudo tcpdump -i eth0 -w eth0_capture.pcap -U > /dev/null 2>&1 & nohup sudo tcpdump -i eth1 -w eth1_capture.pcap -U > /dev/null 2>&1 &
To stop the captures later, find the process IDs with ps aux | grep tcpdump and kill them with kill <PID>.
The easiest tool for this is mergecap (part of the Wireshark toolset). It automatically sorts packets by timestamp, so your merged file will have traffic in chronological order.
First, install the Wireshark utilities if you don’t have them:
- Debian/Ubuntu:
sudo apt install wireshark-common - RHEL/CentOS:
sudo yum install wireshark
Then run the merge command:
mergecap -w combined_capture.pcap eth0_capture.pcap eth1_capture.pcap
The -w flag specifies your output file, followed by the list of captures you want to combine.
If you don’t have mergecap, you can use tshark as an alternative:
tshark -r eth0_capture.pcap -w combined_capture.pcap && tshark -r eth1_capture.pcap -w combined_capture.pcap -a duration:0 -R ""
But mergecap is far simpler, so it’s the recommended option.
Double-check that the merged file contains traffic from both interfaces and is ordered correctly:
tcpdump -r combined_capture.pcap -n
Or if you have access to a graphical interface, open combined_capture.pcap in Wireshark to visually confirm everything looks right.
Extra Tips
- If you only want to capture specific traffic (e.g., TCP packets), add a filter to your
tcpdumpcommand:sudo tcpdump -i eth0 tcp -w eth0_tcp_capture.pcap - To reduce packet loss during capture, increase the buffer size with
-B 4096(sets a 4MB buffer; adjust as needed) - Make sure you have enough disk space—long-running captures can create very large
.pcapfiles!
内容的提问来源于stack exchange,提问作者Luke Devon

