Your command should work, maybe there's a bug. Use tshark (wireshark package) instead: tshark -i eth0 -b duration:3600 -b filesize:102400 -s 65535 -w trace.pcap The created filenames are based on the filename given with the -w option, the number of th