Wireshark mailing list archives

Re: How to get rid of "Linux cooked capture" ?


From: Sake Blok <sake () euronet nl>
Date: Wed, 7 Jul 2010 12:40:12 +0200

On 7 jul 2010, at 12:16, Jeanne Clément wrote:

I would like a pcap capturing every packet on eth0 and lo. For this there is “any”, but this kind of capture brings a 
“Linux cooked capture” layer and I don’t what it at all.
I want a true Ethernet layer and I don’t mind if the address is 00:00:00:00:00:00 for packets issued from lo.

You could create two separate tracefiles. One for eth0 and one for lo and then merge the two with mergecap.

Cheers,


Sake


___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: