Home page logo

wireshark logo Wireshark mailing list archives

Re: PCap-NG support in Wireshark and Tshark
From: Guy Harris <guy () alum mit edu>
Date: Sun, 29 Dec 2013 11:21:04 -0800

On Dec 29, 2013, at 3:41 AM, Guy Harris <guy () alum mit edu> wrote:

So it's more like "it might, or might not, be possible to read from a pipe here, depending on the file type and the 
contents of the file".

Note also that there are file formats that *cannot* be read from a pipe, as even reading the file once, from the first 
packet to the last, requires seeking forward and then backward.  This includes "NetXRay" format (as used by the old 
network analyzer of the same name, as well as by the Windows Sniffer applications) and Network Monitor format.

Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]