tcpdump -i wlan0 -w /tmp/wlan0.pcap -C 50 -A -n -K '(tcp[tcpflags] & (tcp-syn) != 0) \
or ((tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x47455420) and less 1024) \
or ((tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x504F5354) and less 1024)' &
- We are a facing an issue. Capturing all traffic demands huge amount of disk space. We do not have it. So, choose only every packet matching the start of a connection. This is the TCP SYN condition.
- This is the equivalent to GET HTTP method. And capture only if less than 1 Kilobyte.
- This is the equivalent to POST HTTP method. And capture only if less than 1 Kilobyte.