how to split a pcap file into a set of smaller ones

Posted by facha on Server Fault See other posts from Server Fault or by facha
Published on 2010-04-13T08:19:29Z Indexed on 2012/07/05 9:18 UTC
Read the original article Hit count: 385

Filed under:
|

I have a huge pcap file (generated by tcpdump). When I try to open it in wireshark, the program just gets unresponsive. Is there a way to split a file in set of smaller ones to open them one by one? The traffic captured in a file is generated by two programs on two servers, so I can't split the file using tcpdump 'host' or 'port' filters. I've also tried linux 'split' command :-) but with no luck. Wireshark wouldn't recognize the format.

© Server Fault or respective owner

Related posts about tcpdump

Related posts about pcap