美文网首页
CentOS7中wireshark-3.0的使用——(二)pca

CentOS7中wireshark-3.0的使用——(二)pca

作者: funOfFan | 来源:发表于2021-02-25 09:49 被阅读0次
    1. 保证当前环境已经安装了3.0版本的wireshark,可参考前文《CentOS7中wireshark-3.0的使用——(一)安装》
    • 输入editcap,能够自动补全
    1. 准备一个较大的测试用pcapng文件,本文中使用area2.pcapng
    2. 将pcapng文件转换成suricata支持的pcap文件,并切分
    • editcap -F libpcap area2.pcapng area2.pcap
    • editcap -c 1000 ./area2.pcap area2pcap/train_area2.pcap, -c参数指定分割成多少个小的pcap文件
    • 切分完成后,查看切分效果如下
        [root@localhost ~]# ls area2pcap/
        train_area2_00000_20210104202426.pcap
        train_area2_00001_20210104202441.pcap
        train_area2_00002_20210104202459.pcap
        train_area2_00003_20210104202522.pcap
        train_area2_00004_20210104202549.pcap
        train_area2_00005_20210104202619.pcap
        train_area2_00006_20210104202649.pcap
        train_area2_00007_20210104202714.pcap
        train_area2_00008_20210104202748.pcap
        train_area2_00009_20210104202815.pcap
        train_area2_00010_20210104202903.pcap
        train_area2_00011_20210104203043.pcap
        train_area2_00012_20210104203219.pcap
        train_area2_00013_20210104203348.pcap
        train_area2_00014_20210104203507.pcap
        train_area2_00015_20210104203617.pcap
        train_area2_00016_20210104203727.pcap
        train_area2_00017_20210104203805.pcap
        train_area2_00018_20210104203822.pcap
        train_area2_00019_20210104203834.pcap
        train_area2_00020_20210104203844.pcap
        train_area2_00021_20210104203852.pcap
        train_area2_00022_20210104203901.pcap
        train_area2_00023_20210104203911.pcap
        train_area2_00024_20210104203919.pcap
        train_area2_00025_20210104203935.pcap
        train_area2_00026_20210104203956.pcap
        train_area2_00027_20210104204028.pcap
        train_area2_00028_20210104204056.pcap
        train_area2_00029_20210104204127.pcap
        train_area2_00030_20210104204206.pcap
        train_area2_00031_20210104204243.pcap
        train_area2_00032_20210104204305.pcap
        train_area2_00033_20210104204344.pcap
        train_area2_00034_20210104204438.pcap
        train_area2_00035_20210104204500.pcap
        train_area2_00036_20210104204541.pcap
        train_area2_00037_20210104204609.pcap
        train_area2_00038_20210104204641.pcap
        train_area2_00039_20210104204703.pcap
        train_area2_00040_20210104204719.pcap
        train_area2_00041_20210104204731.pcap
        train_area2_00042_20210104204740.pcap
        train_area2_00043_20210104204750.pcap
        train_area2_00044_20210104204758.pcap
        train_area2_00045_20210104204806.pcap
        train_area2_00046_20210104204813.pcap
        train_area2_00047_20210104204820.pcap
        train_area2_00048_20210104204828.pcap
        train_area2_00049_20210104204836.pcap
        train_area2_00050_20210104204849.pcap
        train_area2_00051_20210104204905.pcap
        train_area2_00052_20210104204923.pcap
        train_area2_00053_20210104204939.pcap
        train_area2_00054_20210104204954.pcap
        train_area2_00055_20210104205007.pcap
        train_area2_00056_20210104205028.pcap
        train_area2_00057_20210104205051.pcap
        train_area2_00058_20210104205114.pcap
        train_area2_00059_20210104205137.pcap
        train_area2_00060_20210104205155.pcap
        train_area2_00061_20210104205208.pcap
        train_area2_00062_20210104205218.pcap
        train_area2_00063_20210104205229.pcap
        train_area2_00064_20210104205242.pcap
        train_area2_00065_20210104205254.pcap
        train_area2_00066_20210104205302.pcap
        train_area2_00067_20210104205310.pcap
        train_area2_00068_20210104205317.pcap
        train_area2_00069_20210104205324.pcap
        train_area2_00070_20210104205330.pcap
        ...
      
      

    参考文章:

    相关文章

      网友评论

          本文标题:CentOS7中wireshark-3.0的使用——(二)pca

          本文链接:https://www.haomeiwen.com/subject/husyfltx.html