Unix Technical Forum

exporting snoop output to a .cap

This is a discussion on exporting snoop output to a .cap within the Sun Solaris Hardware forums, part of the Solaris Operating System category; --> Hi, I'd like to know if we can use snoop and export the capture in a format (like *cap) ...


Go Back   Unix Technical Forum > Unix Operating Systems > Solaris Operating System > Sun Solaris Hardware

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-16-2008, 01:18 PM
Veni
 
Posts: n/a
Default exporting snoop output to a .cap

Hi,

I'd like to know if we can use snoop and export the capture in a format
(like *cap) which can be read by a packet analyser like Etheral or perhaps
EtherDetect. I may not have permission to install etheral on one of my
servers but would like to capture the packets and
export it for analysis of snmp packets. thanks for any advice.

regards, Veni
inveni@hotmail.com


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 01-16-2008, 01:18 PM
Scott Howard
 
Posts: n/a
Default Re: exporting snoop output to a .cap

In comp.unix.solaris Veni <inveni@hotmail.com> wrote:
> I'd like to know if we can use snoop and export the capture in a format
> (like *cap) which can be read by a packet analyser like Etheral or perhaps
> EtherDetect. I may not have permission to install etheral on one of my
> servers but would like to capture the packets and
> export it for analysis of snmp packets. thanks for any advice.


Ethereal will read snoop output files, so just :
snoop -o /tmp/snoop.output

Scott
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 01-16-2008, 01:18 PM
Doug McIntyre
 
Posts: n/a
Default Re: exporting snoop output to a .cap

"Veni" <inveni@hotmail.com> writes:
> I'd like to know if we can use snoop and export the capture in a format
>(like *cap) which can be read by a packet analyser like Etheral or perhaps
>EtherDetect. I may not have permission to install etheral on one of my
>servers but would like to capture the packets and
>export it for analysis of snmp packets. thanks for any advice.


Ethereal can read snoop files directly. But if you have something else
that needs pcap file format, ethereal also comes with a util called
mergecap that can read tons of different input file types and output
stock pcap files.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 01-16-2008, 01:19 PM
aryzhov
 
Posts: n/a
Default Re: exporting snoop output to a .cap

"Veni" <inveni@hotmail.com> wrote in message news:<cklf3e$s5h$1@mawar.singnet.com.sg>...
> Hi,
>
> I'd like to know if we can use snoop and export the capture in a format
> (like *cap) which can be read by a packet analyser like Etheral or perhaps
> EtherDetect. I may not have permission to install etheral on one of my
> servers but would like to capture the packets and
> export it for analysis of snmp packets. thanks for any advice.


You need root permissions to run snoop, anway..
Back to topic: I never tried this, but with snoop, you can dump
raw packets (matching the specific rules, if you want) into the file,
and the other analyser PROBABLY can read raw packets from the file
instead of wire.

Regards,
Andrei
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 11:56 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com