@networkchuck: You’ve heard of tcpdump and tshark, but you need to try termshark! It’s a full terminal user interface for tshark that lets you inspect pcaps right in your CLI. You can even use your mouse to click and filter for things! Use it when you are stuck in a remote SSH session and need the power of Wireshark without a GUI. Go try it NOW!!