The idea was to capture the tcp message and prepend it with current timestamp and log it to files. I was able to achieve it. But now I have another issue. When I try to monitor the sockets on localhost it works even after giving the ip address of the server. But when I run tcpflow to monitor sockets on remote server tcpflow is not working.
My tcpflow command is :
tcpflow -c -i any host 172.xx.xxx.111 and tcp dst portrange 1000-65000 and src portrange 1000-65000
If I run the above command from the same machine it works but if I run it from another server it does not work. Can you please help me how to make this work?
thanks