Wireshark mailing list archives
Re: How to get rid of "Linux cooked capture" ?
From: Sake Blok <sake () euronet nl>
Date: Wed, 7 Jul 2010 12:40:12 +0200
On 7 jul 2010, at 12:16, Jeanne Clément wrote:
I would like a pcap capturing every packet on eth0 and lo. For this there is “any”, but this kind of capture brings a “Linux cooked capture” layer and I don’t what it at all. I want a true Ethernet layer and I don’t mind if the address is 00:00:00:00:00:00 for packets issued from lo.
You could create two separate tracefiles. One for eth0 and one for lo and then merge the two with mergecap. Cheers, Sake ___________________________________________________________________________ Sent via: Wireshark-users mailing list <wireshark-users () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-users Unsubscribe: https://wireshark.org/mailman/options/wireshark-users mailto:wireshark-users-request () wireshark org?subject=unsubscribe
Current thread:
- How to get rid of "Linux cooked capture" ? Jeanne Clément (Jul 07)
- Re: How to get rid of "Linux cooked capture" ? Sake Blok (Jul 07)