- 保证当前环境已经安装了3.0版本的wireshark,可参考前文《CentOS7中wireshark-3.0的使用——(一)安装》
- 输入
editcap
,能够自动补全
- 准备一个较大的测试用pcapng文件,本文中使用area2.pcapng
- 将pcapng文件转换成suricata支持的pcap文件,并切分
editcap -F libpcap area2.pcapng area2.pcap
-
editcap -c 1000 ./area2.pcap area2pcap/train_area2.pcap
, -c参数指定分割成多少个小的pcap文件 - 切分完成后,查看切分效果如下
[root@localhost ~]# ls area2pcap/ train_area2_00000_20210104202426.pcap train_area2_00001_20210104202441.pcap train_area2_00002_20210104202459.pcap train_area2_00003_20210104202522.pcap train_area2_00004_20210104202549.pcap train_area2_00005_20210104202619.pcap train_area2_00006_20210104202649.pcap train_area2_00007_20210104202714.pcap train_area2_00008_20210104202748.pcap train_area2_00009_20210104202815.pcap train_area2_00010_20210104202903.pcap train_area2_00011_20210104203043.pcap train_area2_00012_20210104203219.pcap train_area2_00013_20210104203348.pcap train_area2_00014_20210104203507.pcap train_area2_00015_20210104203617.pcap train_area2_00016_20210104203727.pcap train_area2_00017_20210104203805.pcap train_area2_00018_20210104203822.pcap train_area2_00019_20210104203834.pcap train_area2_00020_20210104203844.pcap train_area2_00021_20210104203852.pcap train_area2_00022_20210104203901.pcap train_area2_00023_20210104203911.pcap train_area2_00024_20210104203919.pcap train_area2_00025_20210104203935.pcap train_area2_00026_20210104203956.pcap train_area2_00027_20210104204028.pcap train_area2_00028_20210104204056.pcap train_area2_00029_20210104204127.pcap train_area2_00030_20210104204206.pcap train_area2_00031_20210104204243.pcap train_area2_00032_20210104204305.pcap train_area2_00033_20210104204344.pcap train_area2_00034_20210104204438.pcap train_area2_00035_20210104204500.pcap train_area2_00036_20210104204541.pcap train_area2_00037_20210104204609.pcap train_area2_00038_20210104204641.pcap train_area2_00039_20210104204703.pcap train_area2_00040_20210104204719.pcap train_area2_00041_20210104204731.pcap train_area2_00042_20210104204740.pcap train_area2_00043_20210104204750.pcap train_area2_00044_20210104204758.pcap train_area2_00045_20210104204806.pcap train_area2_00046_20210104204813.pcap train_area2_00047_20210104204820.pcap train_area2_00048_20210104204828.pcap train_area2_00049_20210104204836.pcap train_area2_00050_20210104204849.pcap train_area2_00051_20210104204905.pcap train_area2_00052_20210104204923.pcap train_area2_00053_20210104204939.pcap train_area2_00054_20210104204954.pcap train_area2_00055_20210104205007.pcap train_area2_00056_20210104205028.pcap train_area2_00057_20210104205051.pcap train_area2_00058_20210104205114.pcap train_area2_00059_20210104205137.pcap train_area2_00060_20210104205155.pcap train_area2_00061_20210104205208.pcap train_area2_00062_20210104205218.pcap train_area2_00063_20210104205229.pcap train_area2_00064_20210104205242.pcap train_area2_00065_20210104205254.pcap train_area2_00066_20210104205302.pcap train_area2_00067_20210104205310.pcap train_area2_00068_20210104205317.pcap train_area2_00069_20210104205324.pcap train_area2_00070_20210104205330.pcap ...
参考文章:
网友评论