3
3

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

More than 5 years have passed since last update.

パケットキャプチャが大きくなりすぎる時の対処法

Posted at

キャプチャをフィルタリングして取得する

tshark -w capture.pcap -f 'port 80'

キャプチャを開かずにフィルタリングして取り出す(aaa.capが肥大化したキャプチャ、test.pcapが吐き出し先 windowsで実行した場合)

"C:/Program Files/Wireshark/tshark" 
-r aaa.cap -R http -w test.pcap

Tsharkオプション一覧

tshark option mean
-w [File] 出力ファイルを指定
-d tcp.port=111,http portとプロトコルを紐付(tcp 111portをhttpにする)
-r [inFile] 読み込ませるファイルを指定(-Rオプションでフィルタリング可能)
-f [capture filter] -f 'port 111' port 111のパケットをキャプチャする
3
3
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
3
3

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?