Ask Your Question

How doing the diff between two pcap file and store de results

asked 2019-12-30 09:21:47 +0000

salwa1215 gravatar image

I want to compare the difference between two pcap files and store the difference in another pcap file I used the command files and when I want to open the result file I had a problem with wireshark because its format is not undertood by this later. Here is my command:

diff -ua file1.pcap file2.pcap > file3.pcap

Any help please ?

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted

answered 2019-12-30 09:46:57 +0000

grahamb gravatar image

The result of applying diff to two binary pcap files does not, in general, result in a pcap file.

You'll need to use other tools, e.g. on the Wireshark Wiki Tools list pcap_diff that might help.

You might also consider dumping the pcaps to another format (e.g. text, json, pdml) to then use other diff tools appropriate for that format.

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2019-12-30 09:21:47 +0000

Seen: 1,968 times

Last updated: Dec 30 '19