|
PCAP Reader
|
Reads content from PCAP or PCAPNG files containing Ethernet frames.
| Name | Default Value | Type | Description |
|---|---|---|---|
| build_index | true | bool | Build a packet index while opening the file, which provides the item count, the time range of the stream and seeking. Disable to skip the initial scan of the whole file when large files are only read sequentially. |
| Attribute | Value |
|---|---|
| Plugin Name | pcap_reader.adtffileplugin |
| License | ADTF Subscription |
| Support Mail | suppo.nosp@m.rt@d.nosp@m.igita.nosp@m.lwer.nosp@m.k.net |
| Homepage URL | https://adtf.dev/ |
To use one of the supplied readers, specify the plugin with the --plugin option of the adtf_dattool i.e.:
Note: In this way both pcap file as well as pcapng files can be read.
Note: It is not necessary to specify the reader explicitly because only one reader is defined in this plugin.
Example with readerid:
For each input pcap/pcapng file exactly one ethernet stream is created in ADTF dat file. The naming scheme for the generated streams is as follows:
For pcap input file: PCAP_<base_filename_without_file_extension>
For pcapng input file: PCAPNG_<base_filename_without_file_extension>