RHEL6 Requirements: geoip-1.4.6-1.el6.rf.x86_64.rpm libsmi-0.4.8-4.el6.x86_64.rpm wireshark-1.10.0-1.el6.rft.x86_64.rpm wireshark-gnome-1.10.0-1.el6.rft.x86_64.rpm zlib-1.2.3-29.el6.x86_64.rpm For remote capture readings: coreutils-8.4-43.el6.x86_64.rpm coreutils-libs-8.4-43.el6.x86_64.rpm Create a named pipe: mkfifo /tmp/packet_capture Start wireshark from the command line wireshark -k -i /tmp/packet_capture Run tcpdump over ssh on your remote machine and redirect the packets to the named pipe (find the eth interface): ssh root@source-hostname "tcpdump -s 0 -U -n -w - -i eth0 not port 22" > /tmp/packet_capture Source: http://blog.nielshorn.net/2010/02/using-wireshark-with-remote-capturing/ Filters === Find duplicate ip addresses: arp.duplicate-address-detected Exclude a destination ip address NOT(ip.dst == 10.15.30.114) Exclude a source ip address NOT(ip.src == 10.15.30.114)