Yet another (Alpine-based) Docker container to run TCPDump. Running without parameters will run tcpdump keeping at max one day of pcaps in 15 minute chunks.
Volume with pcaps available at /pcap/
.
$ docker run --rm moncho/tcpdump --help
$ docker run --rm --net=host -v ~/pcap:/pcap moncho/tcpdump
$ docker run --rm --net=host moncho/tcpdump -i any -w - | wireshark -k -i -
$ docker run --rm --net=container:foo moncho/tcpdump -i any --immediate-mode -w - | wireshark -k -i -
Heavily inspired by this post.