Use at(1) to start and kill tcpdump on a sched, then at your convenience look at the pcap file in wireshark? Dave Greg Brown wrote: > Does anyone know of a way to schedule a wireshark start and stop capture the > way you can with a "real" sniffer? > > Greg