Enhanced packet_parser tools
This commit is contained in:
@@ -148,11 +148,24 @@ for pcap in "${pcap_files[@]}"; do
|
||||
|
||||
curr_count=$((curr_count + 1))
|
||||
|
||||
# tshark output frame.protocols
|
||||
tshark -r ${pcap} -T fields -e frame.number -e frame.protocols >>${tmp_file_dir}/tshark_output.txt
|
||||
# tshark output
|
||||
tshark -r ${pcap} -T fields \
|
||||
-e frame.number \
|
||||
-e frame.protocols \
|
||||
-e eth.src \
|
||||
-e eth.dst \
|
||||
-e ip.src \
|
||||
-e ip.dst \
|
||||
-e ipv6.src \
|
||||
-e ipv6.dst \
|
||||
-e tcp.srcport \
|
||||
-e tcp.dstport \
|
||||
-e udp.srcport \
|
||||
-e udp.dstport \
|
||||
>>${tmp_file_dir}/tshark_output.txt
|
||||
|
||||
# packet_parser output frame.protocols
|
||||
./packet_parser -f ${pcap} -p >>${tmp_file_dir}/parser_output.txt
|
||||
# packet_parser output
|
||||
./packet_parser -f ${pcap} -t >>${tmp_file_dir}/parser_output.txt
|
||||
|
||||
# compare tshark and packet_parser output
|
||||
preprocess_tshark_ouput ${tmp_file_dir}/tshark_output.txt ${tmp_file_dir}/tshark_format.txt
|
||||
|
||||
Reference in New Issue
Block a user