PcapSplitter splitting file by both connection and tcp filter doesn't work as expected

69 views
Skip to first unread message

Peter Liu

unread,
Nov 29, 2018, 4:51:20 AM11/29/18
to PcapPlusPlus support
Hello,
    I want the tool to split file by both connection and bpf filter, as I don't want to see UDP, ARP, ICMP...packets in wireshark, so I use following command, but it never really creates files, only prompts "Read and Written 0 packets to 0 files", if I move '-i "tcp"' then it can creates several pcap files. Anyone knows the reason? syntax incorrect? or it only supports either -m or -i, not both?


PcapSplitter -f somepcapfile.pcap -m connection -o ./splitted -i "tcp"

under Ubuntu 16.04.



PcapPlusPlus Support

unread,
Dec 2, 2018, 3:09:55 AM12/2/18
to peter...@gmail.com, pcappluspl...@googlegroups.com
Hi,

I'm sorry for the delayed response.
I tried and it's working on my machine. Could you please share a sample of the pcap you're trying to split?

Thanks,

--
You received this message because you are subscribed to the Google Groups "PcapPlusPlus support" group.
To unsubscribe from this group and stop receiving emails from it, send an email to pcapplusplus-sup...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/pcapplusplus-support/2ce1c311-af69-45a6-9fc2-843be4835ad2%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Dmitry Kshensky

unread,
Oct 26, 2021, 6:56:17 AM10/26/21
to PcapPlusPlus support
The same thing happened for me.

Without bpf filter ("-i") all is fine, applying bpf filter results in "Read and written 0 packets to 0 files"

воскресенье, 2 декабря 2018 г. в 16:09:55 UTC+8, pcappl...@gmail.com:

PcapPlusPlus Support

unread,
Oct 29, 2021, 5:18:11 AM10/29/21
to PcapPlusPlus support
Can you please share the pcap file you're using? That'd help me investigate the issue
Reply all
Reply to author
Forward
0 new messages