tcpdump mailing list archives
Re: Tools for stripping parts of a pcap file?
From: sthaug () nethelp no
Date: Sun, 13 May 2007 19:17:18 +0200 (CEST)
Well, you can open your pcap file with Wireshark (ethereal), select the packets you want using the filter and saving them using the standard "save as" option. Is it enough or you need something more "scriptable" that can be done from the command-line?
Command line would be preferred. But I'm also wondering if maybe what I wanted to do here was misunderstood. I don't want to simply pick all the GRE packets and save those in pcap format. I want to pick the GRE packets and save them *without* the outer IP + GRE header, in pcap format. Steinar Haug, Nethelp consulting, sthaug () nethelp no - This is the tcpdump-workers list. Visit https://cod.sandelman.ca/ to unsubscribe.
Current thread:
- Tools for stripping parts of a pcap file? sthaug (May 13)
- Re: Tools for stripping parts of a pcap file? Luis Martin Garcia (May 13)
- Re: Tools for stripping parts of a pcap file? Guy Harris (May 13)
- Re: Tools for stripping parts of a pcap file? sthaug (May 13)
- Re: Tools for stripping parts of a pcap file? Luis Martin Garcia (May 13)
- Re: Tools for stripping parts of a pcap file? Bruce M. Simpson (May 13)
- Re: Tools for stripping parts of a pcap file? Luis Martin Garcia (May 13)