Wireshark mailing list archives

Re: Feeding data to Wireshark in real time


From: Guy Harris <guy () alum mit edu>
Date: Tue, 16 Mar 2010 23:48:16 -0700


On Mar 16, 2010, at 10:11 PM, Jaap Keuter wrote:

That's called a pipe.

To give some more detail:

if the application writes a pcap file (complete with file header!) to a named pipe, you can have Wireshark or TShark 
capture from that named pipe, by giving the pathname of the named pipe as the name of the network interface on which to 
capture.
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe


Current thread: