Split pcap to multiple files based on number of packets


Here is a script that can use tshark to split a large pcap to multiple small pcaps  inpcap="test.pcap" max=$(tshark -r $inpcap -n -T fields -e frame.number|tail -1) # This is the number of packets in …

dnstop – top like utility for Fedora and other *nix


For installation : sudo yum install dnstop And now some description: […] dnstop is a libpcap application (ala tcpdump) that displays various tables of DNS traffic on your network. dnstop …

