Find available interfaces === tshark -D Execute tshark on a specific interface (i.e. interface #2 from results of above) === tshark -i 2 Execute unattended tshark scan for 10 seconds (-a = autostop; -w = write to file) === tshark -i 2 -a duration:10 -w 10secs.pcap View 10secs.pcap === type "10secs.pcap" in command prompt Analyze traffic remotely over ssh w/ wireshark === ssh root@server.com 'tshark -f "port !22" -w -' | wireshark -k -i -