yum install wireshark-gnome
mkdir /script/
vi /script/tshark.sh
#!/bin/sh
/usr/sbin/tshark -a duration:86400 -b filesize:20480 -f "udp port 5060" -w /var/www/html/pcap/`date +%F--%T`FILENAME.pcap
chmod -R 777 /script/tshark.sh
mkdir /var/www/html/pcap/
chmod -R 777 /var/www/html/pcap/
date :- to know the exact time of time
================================================== =========================
Crontab -e
######### Wireshark Trace #################
31 10 * * * /script/tshark.sh(This Time should be around 3 minutes more that live time as shown in date)
28 0 * * * /usr/bin/find /var/www/html/pcap/ -type f -name "*.pcap" -mtime +3 -exec rm -f {} \;