PCAP Reader
Loading...
Searching...
No Matches
pcap_reader

Readers

pcap_ethernet_frames

Reads content from PCAP or PCAPNG files containing Ethernet frames.

Properties

Name Default Value Type Description
build_index true bool Build a packet index while opening the file, which provides the item count, the time range of the stream and seeking. Disable to skip the initial scan of the whole file when large files are only read sequentially.

Plugin Attributes

Attribute Value
Plugin Name pcap_reader.adtffileplugin
License ADTF Subscription
Support Mail suppo.nosp@m.rt@d.nosp@m.igita.nosp@m.lwer.nosp@m.k.net
Homepage URL https://adtf.dev/

Usage

To use one of the supplied readers, specify the plugin with the --plugin option of the adtf_dattool i.e.:

adtf_dattool --plugin /path/to/pcap_reader/bin/pcap_reader.adtffileplugin --create file_with_ethernet_data.adtfdat --input /path/to/ethernet_frames.pcap

Note: In this way both pcap file as well as pcapng files can be read.

Note: It is not necessary to specify the reader explicitly because only one reader is defined in this plugin.

Example with readerid:

adtf_dattool --plugin /path/to/pcap_reader/bin/pcap_reader.adtffileplugin --create file_with_ethernet_data.adtfdat --input /path/to/ethernet_frames.pcap --readerid pcap_ethernet_frames

Stream names of read pcap files

For each input pcap/pcapng file exactly one ethernet stream is created in ADTF dat file. The naming scheme for the generated streams is as follows:

For pcap input file: PCAP_<base_filename_without_file_extension>

For pcapng input file: PCAPNG_<base_filename_without_file_extension>