Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Post capture file processing

Status
Not open for further replies.

snoffer

Technical User
Jul 25, 2003
2
GB
I wish to do some post capture processing of some LAN traffic inorder to determine the cause of some problems experienced. I would like to add in some logic along the lines of

IF Packet n field 2 - Packet n field 1 >= y
THEN filter packet
ELSE discard packet from filter

1.Is this easily possibly using filters via Sniffer application OR should I use a batch type process with scripting (Perl, VB etc) to process the capture files.

2.Where can I get a breakdown of the .Cap file format sufficient to determine the Layer 2 frame and Layer 3 length fields ?


Regards
Snoffer
 
It sounds like a Display->Data Pattern match would help you out. If you need more info, let me know.

'Making things work better; bit by bit.'
 
Thks Fortunant.

Is this not going to be a bit long winded using data patterns, since I'll have to cater for numerous field lengths (one data pattern for each length in range that I require). Hence the If then else comparison logic.

Available for chat offline if required.

Regards
Will
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top