tcpdump mailing list archives

Re: Tools for stripping parts of a pcap file?


From: sthaug () nethelp no
Date: Sun, 13 May 2007 19:17:18 +0200 (CEST)

Well, you can open your pcap file with Wireshark (ethereal), select
the packets you want using the filter and saving them using the
standard "save as" option.

Is it enough or you need something more "scriptable" that can be done
from the command-line?

Command line would be preferred. But I'm also wondering if maybe what I
wanted to do here was misunderstood. I don't want to simply pick all the
GRE packets and save those in pcap format. I want to pick the GRE packets
and save them *without* the outer IP + GRE header, in pcap format.

Steinar Haug, Nethelp consulting, sthaug () nethelp no
-
This is the tcpdump-workers list.
Visit https://cod.sandelman.ca/ to unsubscribe.


Current thread: