Ethereal

Re: [Ethereal-users] Ethereal summary format
Google
 
Web Ethereal.com

Home | Introduction | Documentation | Lists | FAQ | Development | Wiki | Bugs

Ethereal-users: April 2002


On Sat, Apr 06, 2002 at 05:35:22PM -0600, George Sanderson wrote:
> Just an initial one line header for the print output.  For example:
> Etherreal version 0.92, summary print captured on 01/01/03 13:41:01.01

Where is the information in that header for the "output format"?

Note that the "captured on" information isn't necessarily *available* -
libpcap capture files (libpcap format is the native format of Ethereal)
have time stamps for packets, not for the capture as a whole.

> What about my previous question:
> 
> Is there an available application or script which can take a binary capture
> file as input and generate a custom summary text file output?

I don't know of any, offhand.  There might be some that can take
libpcap-format capture files and produce statistical information, such
as ntop:

	http://www.ntop.org/ntop.html



Powered by MHonArc 2.6.10