Opening TCP dump files using pcap libraries
I want to read through a tcp dump file and print out the packet lengths and their start and end time or just time stamps. I know that pcap libraries can do this. But I could not find a concrete example of opening a dump file and processing it for that information. I am okay with any languages and platform.
java c++ network-programming pcap tcpdump
add a comment |
I want to read through a tcp dump file and print out the packet lengths and their start and end time or just time stamps. I know that pcap libraries can do this. But I could not find a concrete example of opening a dump file and processing it for that information. I am okay with any languages and platform.
java c++ network-programming pcap tcpdump
do you want to write wireshark-like program ( wireshark.org ) ?
– PiotrNycz
Nov 21 '12 at 23:22
hi if wireshark can give me what I want I dont need to write a program, I just want the packet size and timestamp.
– P basak
Nov 23 '12 at 0:23
add a comment |
I want to read through a tcp dump file and print out the packet lengths and their start and end time or just time stamps. I know that pcap libraries can do this. But I could not find a concrete example of opening a dump file and processing it for that information. I am okay with any languages and platform.
java c++ network-programming pcap tcpdump
I want to read through a tcp dump file and print out the packet lengths and their start and end time or just time stamps. I know that pcap libraries can do this. But I could not find a concrete example of opening a dump file and processing it for that information. I am okay with any languages and platform.
java c++ network-programming pcap tcpdump
java c++ network-programming pcap tcpdump
edited Jan 2 at 3:39
Cœur
19k9112154
19k9112154
asked Nov 21 '12 at 22:21
P basakP basak
2,211102948
2,211102948
do you want to write wireshark-like program ( wireshark.org ) ?
– PiotrNycz
Nov 21 '12 at 23:22
hi if wireshark can give me what I want I dont need to write a program, I just want the packet size and timestamp.
– P basak
Nov 23 '12 at 0:23
add a comment |
do you want to write wireshark-like program ( wireshark.org ) ?
– PiotrNycz
Nov 21 '12 at 23:22
hi if wireshark can give me what I want I dont need to write a program, I just want the packet size and timestamp.
– P basak
Nov 23 '12 at 0:23
do you want to write wireshark-like program ( wireshark.org ) ?
– PiotrNycz
Nov 21 '12 at 23:22
do you want to write wireshark-like program ( wireshark.org ) ?
– PiotrNycz
Nov 21 '12 at 23:22
hi if wireshark can give me what I want I dont need to write a program, I just want the packet size and timestamp.
– P basak
Nov 23 '12 at 0:23
hi if wireshark can give me what I want I dont need to write a program, I just want the packet size and timestamp.
– P basak
Nov 23 '12 at 0:23
add a comment |
1 Answer
1
active
oldest
votes
You want pcap_open_offline(). There's a man page for it, and here's an example of using it.
Note that the example program is assuming that the file is an Ethernet capture (without bothering to check whether it is) and that there are neither IP or TCP options (i.e., neither the IP nor TCP header is guaranteed to be exactly 20 bytes long).
– user862787
Nov 22 '12 at 18:45
add a comment |
Your Answer
StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f13503038%2fopening-tcp-dump-files-using-pcap-libraries%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
You want pcap_open_offline(). There's a man page for it, and here's an example of using it.
Note that the example program is assuming that the file is an Ethernet capture (without bothering to check whether it is) and that there are neither IP or TCP options (i.e., neither the IP nor TCP header is guaranteed to be exactly 20 bytes long).
– user862787
Nov 22 '12 at 18:45
add a comment |
You want pcap_open_offline(). There's a man page for it, and here's an example of using it.
Note that the example program is assuming that the file is an Ethernet capture (without bothering to check whether it is) and that there are neither IP or TCP options (i.e., neither the IP nor TCP header is guaranteed to be exactly 20 bytes long).
– user862787
Nov 22 '12 at 18:45
add a comment |
You want pcap_open_offline(). There's a man page for it, and here's an example of using it.
You want pcap_open_offline(). There's a man page for it, and here's an example of using it.
answered Nov 22 '12 at 0:02
whammawhamma
5,49311018
5,49311018
Note that the example program is assuming that the file is an Ethernet capture (without bothering to check whether it is) and that there are neither IP or TCP options (i.e., neither the IP nor TCP header is guaranteed to be exactly 20 bytes long).
– user862787
Nov 22 '12 at 18:45
add a comment |
Note that the example program is assuming that the file is an Ethernet capture (without bothering to check whether it is) and that there are neither IP or TCP options (i.e., neither the IP nor TCP header is guaranteed to be exactly 20 bytes long).
– user862787
Nov 22 '12 at 18:45
Note that the example program is assuming that the file is an Ethernet capture (without bothering to check whether it is) and that there are neither IP or TCP options (i.e., neither the IP nor TCP header is guaranteed to be exactly 20 bytes long).
– user862787
Nov 22 '12 at 18:45
Note that the example program is assuming that the file is an Ethernet capture (without bothering to check whether it is) and that there are neither IP or TCP options (i.e., neither the IP nor TCP header is guaranteed to be exactly 20 bytes long).
– user862787
Nov 22 '12 at 18:45
add a comment |
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f13503038%2fopening-tcp-dump-files-using-pcap-libraries%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
do you want to write wireshark-like program ( wireshark.org ) ?
– PiotrNycz
Nov 21 '12 at 23:22
hi if wireshark can give me what I want I dont need to write a program, I just want the packet size and timestamp.
– P basak
Nov 23 '12 at 0:23