Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] mutlpile traces in a single pcap file - how to split?

From: Mahesh Thiagarajan <mahesh.thiagarajan@xxxxxxxxxx>
Date: Fri, 25 Sep 2009 12:01:05 +0530
Hi,

I am analyzing a PCAP file that contains mac layer to phy layer (the mac and cap exist on different processors and communicate over ethernet)traces of multiple machines.
The frames of both machines look alike, in terms of ethernet source , destination address etc.

Question:

1. How  to now split the trace file into individual machine traces ?

Thanks,
Mahesh