Wireshark mailing list archives

Re: Pcap file isn't a capture file in a format TShark understands


From: kahou lei <kahou82 () gmail com>
Date: Fri, 22 Jan 2010 10:06:51 -0800

*From*: Guy Harris <guy@xxxxxxxxxxxx <guy@DOMAIN.HIDDEN>>
*Date*: Fri, 22 Jan 2010 09:56:09 -0800

On Jan 21, 2010, at 4:43 PM, kahou lei wrote:

Looks like I have an invalid file format.

Yes, you have a file that's not a valid pcap file; either it's not a
pcap file, or it was a pcap file but got damaged somehow.

How were those files created?

Can someone please advice what I should do in order to fix this?

What happens if you run the command "file udp.pcap"?



This file is captured by another machine. I try to use tshark and
wireshark with this file on another machine which is not the captured
one and it works.


If I run "file udp.pcap", it will show the following:


udp.pcap: data


Thanks,

Kahou
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

Current thread: