Tcpdump
by lmarco from LinuxQuestions.org on (#4RR8B)
My experience is very basic in this area so I would like to know what are your favorite or recommended tcpdump switches if you want to learn what kind of traffic is going to and from a particular host. I would like to save this output and, over time, learn what is normal and what is not about a particular host's activities. I'm in a manufacturing company, about 70 Windows hosts.
Thanks everyone.


Thanks everyone.