This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hello! I have a server for storing the pcap-files (few hundreds) of sniffered interfaces. And I'd like to extract needed data from this pcap-files. Just for example: I have 200 pcap-files 50 MB each. It's needed to search all ICMP-pings from IP1 to IP2 and answeres. Currently I learn the possibility of using of script-languages and tshark-commands. May be other ways exists? What are the variants how I can do it?

asked 05 May '14, 02:56

factorial's gravatar image

factorial
26448
accept rate: 0%


Currently I learn the possibility of using of script-languages and tshark-commands.

that's basically the only option to do it in an automatic way, besides reading the pcap file directly with your own software. So, go ahead with that approach.

Regards
Kurt

permanent link

answered 05 May '14, 05:37

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×122
×91
×3
×2

question asked: 05 May '14, 02:56

question was seen: 1,523 times

last updated: 05 May '14, 05:37

p​o​w​e​r​e​d by O​S​Q​A