When Your Server Suddenly Overloads: Where Do You Look?
In the middle of the night, Telegram alert notifications ring continuously. Server CPU hits 100%, network bandwidth is fully saturated, and application responses become abnormally sluggish. You quickly SSH into the server, run netstat, and see thousands of TCP connections opening in rapid succession.
On a personal workstation, you can easily launch Wireshark to filter packets through a graphical interface. But on a production server accessed via SSH, you are confined to a plain monochrome terminal. Relying on tcpdump floods your screen with raw logs moving as fast as a waterfall, making it cumbersome to dissect application-layer (L7) details. This is precisely where Tshark shines.
I once spent nearly three hours diagnosing a sophisticated SSH brute-force incident across a web server cluster. Ever since that painful lesson, Tshark has been the very first tool I install on every managed server.
What Is Tshark and Why Replace tcpdump with It?
Put simply, Tshark is the command-line interface (CLI) counterpart of Wireshark. Both share the exact same protocol dissection libraries. Any protocol Wireshark can analyze, Tshark can dissect with equal fluency.
While tcpdump is ubiquitous and pre-installed on most Linux distributions, Tshark stands out across three critical areas:
- Deep Application-Layer (Layer 7) Inspection: Tshark natively extracts fields from HTTP headers, DNS queries, TLS Handshake certificates, or SSH payloads without requiring complex string-parsing scripts.
- Extremely Powerful Display Filters: You can reuse the full, familiar syntax of Wireshark, such as
http.request.method == "POST"ordns.flags.response == 0. - Customizable Data Extraction: Easily isolate fields like source IP, HTTP status codes, or User-Agent headers into formatted columns to pipe directly into
grep,awk, andsort.
Hands-on: Capturing and Investigating Packets with Tshark
1. Installing Tshark on Linux
On Ubuntu or Debian, install it quickly via APT:
sudo apt update
sudo apt install -y tshark
During the installation process, the system prompts whether non-root users should be allowed to capture packets. Select Yes, then add your current user to the wireshark group so you do not have to prepend sudo to every command:
sudo usermod -aG wireshark $USER
# Log out and log back in via SSH for the new permissions to take effect
2. Identifying Network Interfaces and Capturing Live Traffic
First, list the available active network interfaces:
tshark -D
The system displays interfaces such as 1. eth0, 2. lo (loopback). Assuming your primary outbound network interface is eth0, start monitoring live traffic:
tshark -i eth0
The screen streams live packets traversing the network interface. Press Ctrl + C whenever you want to stop.
3. Filtering Data Fields with the -T fields Option
Instead of scanning lengthy raw log streams, the -T fields option lets you isolate only the necessary data points:
tshark -i eth0 -T fields -e ip.src -e ip.dst -e _ws.col.Protocol -e _ws.col.Info
The command above prints four distinct columns: Source IP, Destination IP, Protocol, and Packet Summary Information, cleanly separated by tabs.
4. Scenario 1: Detecting SYN Port Scans
When an attacker uses Nmap to scan your server ports (in SYN scan mode), they flood TCP SYN packets without returning ACK packets to complete the three-way handshake. You can isolate these specific packets:
tshark -i eth0 -Y "tcp.flags.syn == 1 and tcp.flags.ack == 0" -T fields -e ip.src -e tcp.dstport
If an unknown IP address continuously sends packets targeting dozens of different ports (21, 22, 80, 443, 3306, 8080…) within just 1–2 seconds, your server is almost certainly undergoing reconnaissance for vulnerabilities.
5. Scenario 2: Tracing SSH Brute-Force Attacks
When an attacker runs an automated password-guessing tool against SSH (such as Hydra), connection attempts to port 22 spike abruptly. The command below captures and aggregates the top IP addresses connecting to port 22 over a 20-second window:
tshark -i eth0 -a duration:20 -Y "tcp.dstport == 22 and tcp.flags.syn == 1" -T fields -e ip.src | sort | uniq -c | sort -nr
Breakdown of each parameter:
-a duration:20: Automatically terminates after 20 seconds.-Y "tcp.dstport == 22 and tcp.flags.syn == 1": Filters only TCP handshake initialization packets hitting the SSH port.sort | uniq -c | sort -nr: Groups and sorts IP addresses in descending order of connection frequency.
If you spot an IP initiating 50–100 requests within 20 seconds, you can immediately block it with iptables -A INPUT -s <ATTACKER_IP> -j DROP or ufw deny from <ATTACKER_IP>.
6. Scenario 3: Detecting Data Exfiltration via DNS (DNS Tunneling)
Malware and botnets frequently exploit DNS queries to covertly exfiltrate data or communicate with Command and Control (C2) servers, as UDP port 53 is rarely blocked by firewalls. You can monitor every domain name resolution requested by the server:
tshark -i eth0 -Y "dns.flags.response == 0" -T fields -e ip.src -e dns.qry.name
If you notice subdomains featuring randomized strings or abnormally long Base64-encoded strings (for example: dGVzdC1kYXRh.malicious-domain.com), there is a high probability the server has been compromised and is leaking data behind the scenes.
7. Capturing Traffic to a .pcap File for In-Depth Analysis
During an active security incident, the safest approach is dumping raw network traffic directly into a .pcap file before performing thorough post-mortem analysis:
# Capture exactly 10,000 packets and write to incident.pcap
sudo tshark -i eth0 -c 10000 -w /tmp/incident.pcap
You can then perform offline analysis on this file directly on the server at any time:
# Quickly filter HTTP requests returning 4xx or 5xx error codes
tshark -r /tmp/incident.pcap -Y "http.response.code >= 400" -T fields -e ip.src -e http.response.code -e http.request.uri
Conclusion
Tshark serves as an indispensable magnifying glass right inside your Linux terminal. You don’t need to transfer gigabytes of packet dumps back to your local machine just to filter a few log lines in Wireshark. Once you master Tshark’s core filters, you can rapidly isolate root causes and proactively defend your servers against unexpected attacks.
