簡單範例 mergecap,wireshark 付屬程式

 

man mergecap


 

讀 capture1,capture2,capture3,capture4,只要前 35 字節,按封包時間排序,以 Sun snoop 格式精密合並至 merge_snoop

mergecap -s 35 -v -F snoop -w merge_snoop capture1 capture2 capture3 capture4

讀 capture1,capture2,capture3,capture4,不必按封包時間排序,精密合並至 merge_file
mergecap -v -a -w merge_file capture1 capture2 capture3 capture4

讀 capture1,capture2,capture3,按封包時間排序,以 Ethernet 封裝精密合並至 merge_encap

mergecap -v -T ether -w merge_encap capture1 capture2 capture3

 

Etherreal Packet Sniffing, Angela Orebaugh

你可能感兴趣的:(wireshark,libpcap,editcap,text2pcap,mergecap)