Linux arpwatch command
The Linux arpwatch command is used to monitor ARP records on the network.
ARP (Address Resolution Protocol) is a protocol used to resolve IP addresses and hardware addresses of network devices.
arpwatch can monitor and record ARP packets on the local area network, and report changes detected via e-mail.
Syntax
arpwatch [-d][-f<记录文件>][-i<接口>][-r<记录文件>]
Options:
- -d Enable debug mode.
- -f<record file> Set the file to store ARP records; default is /var/arpwatch/arp.dat.
- -i<interface> Specify the interface to monitor ARP; default interface is eth0.
- -r<record file> Read ARP records from the specified file instead of monitoring from the network.
- -n Specify additional local networks
- -u Specify user and user group
- -e Send email to the specified user instead of the default root user
- -s Specify a username as the return address instead of the default root user
Examples
Monitor ARP information on network interface eth0
arpwatch -i eth0
Monitor ARP information and record related data to the corresponding file
# arpwatch -i eth0 -f a.log //将信息记录到a.log中Other Extensions
Linux Command Reference