抓取web服务器
tshark -n -t a -R http.request -T fields -e "frame.time" -e "ip.src" -e "http.host" -e "http.request.method" -e "http.request.uri"
抓取eno16777736网卡mysql的查询,默认是3306
[root@worker1 dir6]# tshark -n -i eno16777736 -R 'mysql.query' -T fields -e "ip.src" -e "mysql.query"
抓取eno16777736网卡mysql的查询,若不是3306端口,是3307端口
[root@worker1 dir6]# tshark -n -i eno16777736 -port 3307 -d tcp.port==3307,mysql -z "proto,colinfo,mysql.query,mysql.query"