confirmed, ntop can capture from a tcpdump file.
-f | --traffic-dump-file
By default, ntop captures traffic from network interface cards (NICs) or from net�
Flow/sFlow probes. However, ntop can also read data from a file - typically a tcp�
dump capture or the output from one of the ntop packet capture options.
regards, Kenneth
Miguel A Paraz wrote:
On Wed, 10 Nov 2004 12:58:26 +0800, Bopolissimus Platypus Jr
<[EMAIL PROTECTED]> wrote:
when you -r them, you can specify different output parameters, so you can print just the source/dest, for instance, e.g., with
-e
which will print only the link level header, which is going
to be pretty easy to grab source/destination and port information
from. which seems to be what you want to do.
Yup... but the sizes are not there. I found a page saying you have to
sum it up yourself. Was wondering if a tool exists that can do this
without extra code, or else... hello libpcap!
--
Philippine Linux Users' Group (PLUG) Mailing List
[EMAIL PROTECTED] (#PLUG @ irc.free.net.ph)
Official Website: http://plug.linux.org.ph
Searchable Archives: http://marc.free.net.ph
..
To leave, go to http://lists.q-linux.com/mailman/listinfo/plug
..
Are you a Linux newbie? To join the newbie list, go to
http://lists.q-linux.com/mailman/listinfo/ph-linux-newbie
-- Philippine Linux Users' Group (PLUG) Mailing List [EMAIL PROTECTED] (#PLUG @ irc.free.net.ph) Official Website: http://plug.linux.org.ph Searchable Archives: http://marc.free.net.ph . To leave, go to http://lists.q-linux.com/mailman/listinfo/plug . Are you a Linux newbie? To join the newbie list, go to http://lists.q-linux.com/mailman/listinfo/ph-linux-newbie
