Ask Your Question
0

How to set packet metadata in realtime?

asked 2017-11-02 20:20:48 +0000

Stuhgb gravatar image

Hello, I'd like to know if there is a mechanism/interface in tshark to modify packets while they are being live captured and before they are written into a .pcapng file.

What I'd like to accomplish is to set some metadata(I think the opt_comment field would be suitable for that) in the next incomming packet(s) after an external trigger.

If it's not possible with tshark, do you have any ideas how it could be done with another tool?

Thanks in advance!

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted
0

answered 2017-11-03 00:20:52 +0000

Guy Harris gravatar image

Hello, I'd like to know if there is a mechanism/interface in tshark to modify packets while they are being live captured and before they are written into a .pcapng file.

No, there isn't.

What I'd like to accomplish is to set some metadata(I think the opt_comment field would be suitable for that) in the next incomming packet(s) after an external trigger.

If it's not possible with tshark, do you have any ideas how it could be done with another tool?

The only tool I know of that could do that would be a C compiler. :-)

I.e., I know of no packet-capturing tool that will do that for you, so you'd either have to write your own or modify an existing one.

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower

Stats

Asked: 2017-11-02 20:20:48 +0000

Seen: 655 times

Last updated: Nov 03 '17