https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3772
Summary: Feature Request: Support for Appending Packets to
Existing Capture Files
Product: Wireshark
Version: SVN
Platform: Other
OS/Version: All
Status: NEW
Severity: Enhancement
Priority: Low
Component: Wireshark
AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
ReportedBy: tyson.key@xxxxxxxxx
Build Information:
wireshark 1.3.0-SVN-29052
Copyright 1998-2009 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
Compiled with GTK+ 2.14.7, with GLib 2.18.4, with libpcap 1.1-PRE-CVS, with
libz
1.2.3, with POSIX capabilities (Linux), with libpcre 7.8, without SMI, without
c-ares, without ADNS, without Lua, without Python, with GnuTLS 2.4.2, with
Gcrypt 1.4.4, with MIT Kerberos, without GeoIP, without PortAudio, without
AirPcap.
Running on Linux 2.6.28-0.131.rc8.git4.fc11.i686, with libpcap version
1.1-PRE-CVS, GnuTLS 2.4.2, Gcrypt 1.4.4.
Built using gcc 4.3.2 20081105 (Red Hat 4.3.2-7).
--
It may be useful in some cases, to be able to append to, prepend to, or
chronologically inject packets into existing capture files (e.g. when capturing
traffic from related network interfaces, or continuing a capture from the last
time an interface came down/was "lost"), especially given that certain file
formats make this functionality possible (e.g. pcap-ng).
I'm not sure if the ability to capture from multiple interfaces would make this
feature partially redundant though, if it was implemented. (Although I recall
there being discussion about that).
Thanks.
--
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.