Tcpdump cheat sheet
Display packtes from <host> on interface eth0:
tcpdump -i eth1 -n host <HOST>
Save packets to trace file on interface eth0 with the exclusion of SSH traffic:
tcpdump -i eth0 port not 22 -w <path>
Save packets to trace file on interface eth0 - icmp only:
tcpdump -i eth0 icmp -w <path>
To stop:
<Enter>