This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi we get a *.cap file from microsoft Network monitor3.x tools. but it's too large for analysis. when we want to split those file by editcap.exe but no file create. editcap -c 5000 -F netmon2 D:\MicrosoftNTP.cap D:\temp

how to specify the input file type of editcap . the -T -F parameter is only used for output file.

asked 18 Aug, 05:07

neil_hao's gravatar image

neil_hao
2661014
accept rate: 0%


how to specify the input file type of editcap

You can't.

Because you don't have to.

The library that Wireshark, TShark, editcap, capinfos, etc. uses to read capture files figures out the file type for you.

permanent link

answered 18 Aug, 21:28

Guy%20Harris's gravatar image

Guy Harris ♦♦
17.4k335195
accept rate: 19%

thanks, but how to split this file by tshark? after we run script "editcap -c 5000 -F netmon2 D:\MicrosoftNTP.cap D:\temp", the output file is broken and cant opened by wireshark

(20 Aug, 23:17) neil_hao
1

editcap ... the output file is broken and cant opened by wireshark

That would therefore be a bug in editcap - if it writes a file that can't be read by Wireshark, that's a bug.

Please file a but on the Wireshark Bugzilla, and attach the input file you're using, so we can try to reproduce it.

(20 Aug, 23:47) Guy Harris ♦♦
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×33

question asked: 18 Aug, 05:07

question was seen: 419 times

last updated: 20 Aug, 23:47

p​o​w​e​r​e​d by O​S​Q​A