tcpdump mailing list archives

tcpdump output format


From: "Latha G" <lathajee () gmail com>
Date: Mon, 6 Mar 2006 13:40:11 +0530

Hi all,

I have one question about the output format of tcpdump.
How can we know whether the output from the tcpdump is in the correct
format?
Any file is there to know about the format of the output?
The printing of packets on the standard output is tcpdump's implementation
dependent, right?
Is the the output format will be changed from version to version???
Then, where can I find the format of the output?
like for IP packets the output should be like that.....
in that way , i want...

I got the doubt because......
arp packet once i got is,
    13:39:20.680816 arp who-has 172.16.0.136 tell mech_23_28.ac.in
and some other time i got is,
     13:39:20.680816 arp who-has 172.16.0.136 (Broadcast) tell
mech_23_28.ac.in
Any small help be appreciated..

Any document is there which contains implementation details like these?

Thanks in advance...

--
Regards,
Latha.
-
This is the tcpdump-workers list.
Visit https://lists.sandelman.ca/ to unsubscribe.


Current thread: