Linux arpwatch command

Linux 命令大全Linux Command Reference

The Linux arpwatch command is used to monitor ARP records on the network.

ARP (Address Resolution Protocol) is a protocol used to resolve IP addresses and hardware addresses of network devices.

arpwatch can monitor and record ARP packets on the local area network, and report changes detected via e-mail.

Syntax

arpwatch [-d][-f<记录文件>][-i<接口>][-r<记录文件>]

Options:

  • -d Enable debug mode.
  • -f<record file> Set the file to store ARP records; default is /var/arpwatch/arp.dat.
  • -i<interface> Specify the interface to monitor ARP; default interface is eth0.
  • -r<record file> Read ARP records from the specified file instead of monitoring from the network.
  • -n Specify additional local networks
  • -u Specify user and user group
  • -e Send email to the specified user instead of the default root user
  • -s Specify a username as the return address instead of the default root user

Examples

Monitor ARP information on network interface eth0

arpwatch -i eth0

Monitor ARP information and record related data to the corresponding file

# arpwatch -i eth0 -f a.log //将信息记录到a.log中

Linux 命令大全Linux Command Reference

Other Extensions