How to consistently run a monitoring script that will generate PCAPs by running
tcpdump on port 5060?
The run_pcaps process contains 2 bash scripts run_tcpdump.sh and compress_folder.sh.
run_tcpdump.sh
#!/bin/bash # Step 1: Create the Pcaps directory if it doesn't exist if [ ! -d "/opt/pbxware/pw/tmp/Pcaps" ]; then mkdir /opt/pbxware/pw/tmp/Pcaps fi # Step 2: Run tcpdump and save it to a pcap file while true; do filename=$(date +%Y-%m-%d_%H-%M-%S).pcap #filename set as a date/time tcpdump -i any -U -w "/opt/pbxware/pw/tmp/Pcaps/$filename" port 5060 & #running tcpdump on port 5060 and saving it to a pcap that will be named as $filename pid=$! sleep 15 #number of seconds after which a new pcap file will be generated kill $pid done
The idea is to run tcpdump constantly and save the output to a pcap file. The sleep time will define
the number of seconds for each pcap file. In the example above, a new pcap file will be generated
every 15 seconds. These files will be saved on the path /opt/pbxware/pw/tmp/Pcaps, where /Pcaps
folder will be created if it does not exist.
compress_folder.sh
#!/bin/bash
while true; do
folder_size=$(du -s /opt/pbxware/pw/tmp/Pcaps | awk '{print
$1}') #get variable folder_size and get only the numerical part
with awk
if [ $folder_size -gt 1000 ]; then #size of a folder in KB
filename=$(date +%Y-%m-%d_%H-%M-%S).tar.gz #compressed file
will be named as a date e.g. 2023-02-14_10-50-47.tar.gztar -czvf "/opt/pbxware/pw/tmp/$filename"
/opt/pbxware/pw/tmp/Pcaps
rm -rf /opt/pbxware/pw/tmp/Pcaps
mkdir /opt/pbxware/pw/tmp/Pcaps
fi
sleep 600 #amount of time after it will check again
doneThis script will constantly check the folder size (Pcaps) and if it exceeds the set number, it will compress the folder, and delete the original folder.
To run these scripts in the backend, we can run them with commands nohup and &. For example:
nohup ./run_tcpdump.sh &
nohup ./compress_folder.sh &
The & symbol at the end of a command in a shell script is used to run the command in the background, meaning that it continues to run even after the terminal is closed. The nohup command is used to run a command that continues to run after the terminal is closed, even if the terminal session is terminated.
When used together, the nohup command and the & symbol allow you to run a shell script in the background, even after you log out or close the terminal session. This means that the script will continue to run until it is stopped or the system is rebooted.
Also, we can create an alias in ~/.bashrc that will run these 2 scripts at once. E.g. edit ~/.bashrc and
add:
alias run_pcaps='nohup bash run_tcpdump.sh & nohup bash compress_folder.sh &'
Run: source ~/.bashrc
Then, once you enter run_pcaps command in the terminal on PBXware, these 2 scripts will run in the backend until you kill the process with kill -9 $PID.
The compress_folder.sh can be modified to work differently as well – e.g. to compress the folder every 24 hours regardless of the size.
Also, the initial tcpdump command does not capture RTP, but we can change that by modifying the command to add the RTP port range along with SIP 5060 port:
tcpdump -i any -U -w "/opt/pbxware/pw/tmp/Pcaps/$filename" 'port 5060 or portrange 16384-32768' &