Wireshark 1.4 on Windows 7 is missing a several output file formats. According to the documentation there should be ten options but there are only seven - the various *.cap options. I am particularly interested in being able to save in the bfr (Network Observer) format. How can I get this back? Thanks asked 23 Dec '10, 22:44 GPT |
One Answer:
How about this note in the User's Guide:
answered 24 Dec '10, 02:24 Jaap ♦ |
That doesn't say a whole lot, does it? Any ideas on what packet types these are? I would like to try filtering them out to see if I still have the data in which I am interestesd.
Thanks
Unfortunately, to give details, we'd have to say a whole lot - we support a number of capture file formats and link-layer types, and we'd probably have to give a table with one of those being the rows and another being the columns, or something such as that.
In the particular case of .bfr format, the only link-layer types we support are Ethernet and Token Ring. What link-layer type is the capture you're trying to save, and what file format is it? (If it's a capture you made with Wireshark, is it pcap or pcap-ng?)