Can Wireshark convert sflow packets to "normal" traffic
Hi,
I have setup Sflow to send traffik to a server. I started Wireshark, hoping that i could start analyzing the packets, only to find out, that Wireshark doesnt extract the data from the Sflow. It only shows the actual sflow packet. How can i extract/convert the data to look like normal data?
What would "normal data" be? Are you looking for collector stats or something else?
(Note to future readers: the presentation @grahamb linked to shows wireshark-ntop , which includes a Lua plugin for Wireshark to display collector stats.)