Wireshark mailing list archives

Re: PCap-NG support in Wireshark and Tshark


From: Guy Harris <guy () alum mit edu>
Date: Sun, 29 Dec 2013 11:21:04 -0800


On Dec 29, 2013, at 3:41 AM, Guy Harris <guy () alum mit edu> wrote:

So it's more like "it might, or might not, be possible to read from a pipe here, depending on the file type and the 
contents of the file".

Note also that there are file formats that *cannot* be read from a pipe, as even reading the file once, from the first 
packet to the last, requires seeking forward and then backward.  This includes "NetXRay" format (as used by the old 
network analyzer of the same name, as well as by the Windows Sniffer applications) and Network Monitor format.

___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe


Current thread: