Thanks,
The Pcapr Team
> --
> To post to this group, send email to pcapr...@googlegroups.com
> To unsubscribe from this group, send email to
> pcapr-forum...@googlegroups.com
>
> http://www.pcapr.net/
The size of the files is too small which indicates something going
awry during the indexing process. 4K for the terms.db for a 500MB file
doesn't look right. One thing that we've seen from time to time is
that tshark would crash because of state accumulation on very large
pcaps. Splitting them up and letting xtractr stitch the flows across
the pcaps seems to help since we are restarting tshark for each of the
pcap segments. Maybe that's the reason?
Thanks,
The Pcapr Team
---
http://www.pcapr.net
http://twitter.com/pcapr
http://labs.mudynamics.com
Unfortunately the answer is "it depends". Meaning, if tshark doesn't
crash on you, xtractr will happily eat up all of the 500MB of pcaps.
Maybe the simplest way is to install pcapr.Local and dump all these
files into the specified directory and see what happens with the
indexing process. Then selectively you can split them up and
pcapr.Local will automatically discover and index these pcaps.
https://github.com/pcapr-local/pcapr-local
Thanks,
The Pcapr Team