# ...being basically a clarification of dump all packets and list them according to the processes that either sent or received them
and what command could display current running processes relating to eth0
so I can refer back to this when needed.
The question: generate an audit trail that includes captured traffic and process information.
The problem: when capturing packets no process information is stored.
Solution: correlation provides the "glue" between...