Replaying wireshark dump

1,636 views
Skip to first unread message

Rolf Wojtech

unread,
May 2, 2012, 5:34:28 AM5/2/12
to osti...@googlegroups.com

Hello,

I am trying to replay UDP data that I recorded using Wireshark.

All traffic was send to one UDP port and sender and receiver are always the same.

 

However, when I try to import this in Ostinato using the “Open Stream” feature, Ostinato creates many separate streams instead of a single one.

 

This means that changing the target port / IP is virtually impossible (~100000 Streams).

 

Is there any way to force Ostinato to import the dump into ONE stream?

 

Regards, Rolf Wojtech

 

Srivats P

unread,
May 2, 2012, 11:43:44 AM5/2/12
to Rolf Wojtech, osti...@googlegroups.com
Unfortunately not at the moment. When importing a pcap file, each
packet is converted to a stream.

How do the packets in the pcap file differ with respect to each other?
What if you imported just one packet and then modify the stream
manually as required to send several packets?

Srivats
> --
> Get Ostinato News and Updates on Twitter - Follow @ostinato
> (http://twitter.com/ostinato)
> ---------
> You received this message because you are subscribed to the Google Groups
> "ostinato" group.
> To post to this group, send email to osti...@googlegroups.com
> To unsubscribe from this group, send email to
> ostinato+u...@googlegroups.com
> For more options, visit this group at
> http://groups.google.com/group/ostinato?hl=en



--
http://ostinato.org/
@ostinato

Srivats P

unread,
Feb 20, 2013, 12:11:51 PM2/20/13
to skanda, osti...@googlegroups.com, Rolf Wojtech
Are you sure it is the standard pcap format and not the new pcap-ng
format? Ostinato cannot handle the new pcap-ng format.

Check the first 4 bytes of the file. If it is 0xa1b2c3d4 or
0xd4c3b2a1, then it is the pcap format; if it is 0x0A0D0D0A then it is
the new pcap-ng format.

To convert pcap-ng to pcap format you can use editcap or the online
service at http://pcapng.com/

Srivats

On Wed, Feb 20, 2013 at 2:24 PM, skanda <aparna...@gmail.com> wrote:
>
> Hi
> * I'm also trying to replay wireshark dump, however, Open Stream is saying
> that it's not a valid pcap file. I'm able to open it with plain wireshark &
> tshark (-r option). Could you please help?
>
> * When would the feature of replaying the wireshark dump (without separating
> into individual streams) come up?
> To unsubscribe from this group and stop receiving emails from it, send an
> email to ostinato+u...@googlegroups.com.
> For more options, visit https://groups.google.com/groups/opt_out.
>
>



--
http://ostinato.org/
@ostinato
Reply all
Reply to author
Forward
0 new messages