Monitor network traffic with ngrep

When it comes to network monitoring, there are a number of available tools out there. However, one tool that administrators often overlook is the network grep (ngrep) tool.

As a network sniffer or monitor, ngrep is very similar in some respects to tcpdump, but it’s somewhat different because you can use grep-style syntax to filter what you want.

Ngrep’s most basic use is to listen to all traffic on an interface. However, you can extend this quite a bit to narrow down what you’re looking for. Ngrep’s syntax is similar to that of tcpdump. Here’s an example:

$ ngrep port 80 and src host and dst host [Read the rest]

