tshark: perform filters to rip out a pcap from a large pcap

April 13th, 2010 mysurface

One time I been given numbers of very large pcap files, ask me to do some analysis on http traffics. The given pcap is raw traffics pcap capture from servers, most of the packets in the pcap for me is redundant, because I am only interested in http traffics. Opening a large pcap with wireshark [...]

Posted in Network, tshark | Hits: 166146 | 3 Comments »