I thought I would use knoppix 3.2 as a protocol analyzer. I can boot up just fine without any issues. I have my switch setup to port mirror. After I bring up a console in KDE and type: tcpdump about a million packets go flying by the screen so I know that my network card is seeing all traffic. As soon as I try to filter these packets with a command such as: tcpdump -i eth0 host 192.168.1.1 using an actual ip address that I know traffic is going to and from, I don't see anything. I've checked the tcpdump manual but it is as if any expression that is added to the end of tcpdump seems to kill it's ability to see any traffic. Has anyone seen this problem or can confirm that I'm not doing something wrong? I am in the process of getting the latest 3.3 9-24-03 version to see if this makes any difference. I've also tried Ethereal under KDE and as long as I just capture anything to the port everything is seen but when trying to use a filter to limit what's captured it fails also.
thanks in advance,

GIGABYTE A520M DS3H AC AMD AM4 Motherboard mATX
$59.99
GIGABYTE Z790 AORUS ELITE AX LGA 1700 Intel Z790 ATX Motherboard with DDR5
$189.99
Intel H310 LGA1151 8-9th Gen DDR4 M.2 NVMe mATX Motherboard IO Shield Battery
$54.99
ASUS PRIME Z490-V Motherboard Intel Z490 10th gen DDR4 LGA 1200 ATX w/ IO Shield
$84.99
ASUS PRIME B360M-C MicroATX Intel LGA1151 DDR4 HDMI VGA USB RJ-45 Audio
$34.99
MSI B550M PRO-VDH Micro-ATX Motherboard - AMD AM4, Ryzen 5000/4000/3000 Ready, P
$71.49
GIGABYTE B365 HD3 LGA1151 Intel 9th Gen motherboard
$59.99
MSI - B550M PRO-VDH WIFI (Socket AM4) AMD B550 MATX DDR4 Wi-Fi 6 Motherboard ...
$89.99
ASRock IMB-X1314 LGA 1700 Intel W680 DDR4 Quad display Micro-ATX Motherboard
$351.99
Gigabyte GA-B85M-D3H Motherboard
$54.99