I will then use tcpdump and look at the results, looking for the right filter for the version I have.

Launching few instances of tshark for the vlans I want looks a good idea, as wireshark will then synchronize them. The p

Cmaynard, I am sure I am capturing vlan traffic. Actually, the problem is capturing too much traffic. But I will do the

I will stop bugging you for a day and go over the documentation you recommended and do some tests (RTFM). Just as info (

That is really "crazy"... When I use dumpcap using your last suggestion I get: dumpcap -i ens4f0 -f '(ether[12:2] = 0x8

Look: yum list installed | grep libcap compat-libcap1.x86_64 1.10-7.el7 @anaconda/7.4 libcap.x86_64

I must confess that when it comes to dumpcap I am just a dummy. Anyway, I am using CentOS 7 and I did use dumpcap as you

Jaap, I just tested your suggestion using 'vlan and (ether[14:2]&0x0fff != 100 and ether[14:2]&0x0fff != 200)',

NJL, what I am doing is exactly what is suggested on the post. If I understood correctly, you can not capture two VLANs

Vlan filter I am capturing traffic from a trunk mirror. This trunk has over 30 VLANs and I would like to exclude some of