я бы в эту строку: tcpdump -i eth0 host
192.168.1.10 and port 5060 -w dump.cap добавил опцию -G —> tcpdump -i eth0 host
192.168.1.10 and port 5060 -w dump.cap -G 1800
и остановил бы дамп тогда, когда поймал бы интересующие событие.
-G If specified, rotates the dump file specified with the -w option every rotate_seconds seconds. Savefiles will have the name specified by -w which should include a time format as defined by strftime(3). If no time format is speci-
fied, each new file will overwrite the previous.