Wireshark-dev: Re: [Wireshark-dev] 90GB pcap file get last frame time stamp

From: Richard Sharpe <realrichardsharpe@xxxxxxxxx>
Date: Fri, 26 Feb 2021 09:39:00 -0800
On Fri, Feb 26, 2021 at 9:10 AM Raj sekar <mrajsekar@xxxxxxxxx> wrote:
> Hi Everyone!
> Need a help. Is there any library or method to get large pcap file's( offline ) last timestamp.
> I know capinfos can get this. But i want faster than capinfos.
> Any suggestion?

Because each captured frame can be a different length, normally you
would have to skip all the preceding frames to get the timestamp of
the last record.

However, a heuristic approach might be to read the header to get the
capture-length, and then read that much from the end of the file and
look for an appropriate record header ...

On the other hand, I am unaware of any code that does that.

Richard Sharpe