

On Linux you don’t need to be root to capture packets. You shouldn’t run them as root for the same reasons that you shouldn’t run Firefox, OpenOffice, GIMP, or any other similarly-sized application as root. Wireshark is quickly approaching two million lines of code.

sudo chgrp wireshark /usr/sbin/dumpcap.Ĥ Answers.Re-login to apply the group changes or use newgrp wireshark as the normal user to enter the wireshark group.Create group “wireshark” and add yourself to it: sudo groupadd -s wireshark sudo gpasswd -a $USER wireshark.Limiting capture permission to only one group How do I run Wireshark as administrator?.Can I use my 24 inch iMac as a monitor?.How do you check your Internet speed on a Mac?.What is the difference between Wireshark and Tshark?.How do you sniff network traffic on a Mac?.
