tcpdump mailing list archives
"stream" data from tcpdump
From: Gilgamesh Enkidu <ether.header () googlemail com>
Date: Thu, 16 Jul 2009 22:39:22 +0100
I would like to "stream" data from tcpdump to another application. I'm running tcpdump on an interface and doing some pretty tight filtering on it. Occasionally, I would like to run another tool (eg. snort, tshark) on the filtered stream of data. It seems less than ideal to have to run the other tool on the interface and repeat the filtering, rather than taking advantage of the fact that tcpdump has already done it for me. But what is the best way to get my "stream" of filtered data from tcpdump to my other tool? I would rather not write the data to disk. A fifo seemed like a good idea, but it falls down in that when I quit my second tool it kills the original tcpdump. I need to somehow have this "stream" of data available that I can tap into as needed, and not have to worry about interrupting my original tcpdump job. Any ideas? - This is the tcpdump-workers list. Visit https://cod.sandelman.ca/ to unsubscribe.
Current thread:
- "stream" data from tcpdump Gilgamesh Enkidu (Jul 16)
- Re: "stream" data from tcpdump Michael Richardson (Jul 17)