Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-bugs: [Wireshark-bugs] [Bug 2925] New: EditCap and TShark cannot convert " NetScreen snoop text file" format to libpcap; Wireshark can

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: bugzilla-daemon@xxxxxxxxxxxxx
Date: Wed, 1 Oct 2008 05:29:27 -0700 (PDT)

https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2925

           Summary: EditCap and TShark cannot convert "NetScreen snoop text
                    file" format to libpcap; Wireshark can
           Product: Wireshark
           Version: 1.0.3
          Platform: PC
        OS/Version: Windows XP
            Status: NEW
          Severity: Normal
          Priority: Medium
         Component: TShark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: okrasz_news@xxxxx


Build Information:
TShark 1.0.3 (SVN Rev 26134)

Copyright 1998-2008 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled with GLib 2.14.6, with WinPcap (version unknown), with libz 1.2.3,
without POSIX capabilities, with libpcre 7.0, with SMI 0.4.8, with ADNS, with
Lua 5.1, with GnuTLS 2.3.8, with Gcrypt 1.4.1, with MIT Kerberos.

Running on Windows XP Service Pack 3, build 2600, with WinPcap version 4.0.2
(packet.dll version 4.0.0.1040), based on libpcap version 0.9.5.

Built using Microsoft Visual C++ 6.0 build 8804
--

EditCap as well as TShark is not able to convert "NetScreen snoop text file" to
a libpcap format. Suprisingly Wireshark is able to do it (when you use "File ->
Save as"). Please try converting attached trace with following commands:

C:\>"Program Files\Wireshark\editcap.exe" -F libpcap NetScreen.txt t.pcap
editcap: Can't open or create t.pcap: Files from that network type can't be
save
d in that format

C:\>"Program Files\Wireshark\tshark.exe" -F libpcap -r NetScreen.txt -w t.pcap
tshark: The capture file being read can't be written in that format.


-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.

  • Follow-Ups:
    • [Wireshark-bugs] [Bug 2925] EditCap and TShark cannot convert "NetScreen snoop text file" format to libpcap; Wireshark can
      • From: bugzilla-daemon
  • Prev by Date: [Wireshark-bugs] [Bug 2722] Follow TCP stream detects FIN flags as missing byte
  • Next by Date: [Wireshark-bugs] [Bug 2925] EditCap and TShark cannot convert "NetScreen snoop text file" format to libpcap; Wireshark can
  • Previous by thread: [Wireshark-bugs] [Bug 2743] tshark, when run without -w, should have dumpcap pipe the packets to it
  • Next by thread: [Wireshark-bugs] [Bug 2925] EditCap and TShark cannot convert "NetScreen snoop text file" format to libpcap; Wireshark can
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation