This thread was very helpful-- but it wasn't working for me. It only took the first -b flag, I had to make the duration/filesize option a "-a" flag and only the "files:#" on the -b flag.
I went with the filesize rotation rather than a duration because the files from the duration of 120 seconds ranged from a few mb to 500mb on my small business network. A 500mb file in Wireshark is not easy to work with!
I want to have several hours worth to go back and look at, so we'll see how this will work. Here's my command:
dumpcap -a filesize:6000 -b files:150 -i eth3 -w /var/dumpcap/eth3
-Kevin
/*“ I am looking for a lot of men who have an infinite capacity to not know what can't be done. ” -- Henry Ford */