Contents
How do I read a pcap file in Linux?
tcpshow reads a pcap file created from utilities like tcpdump , tshark , wireshark etc , and provides the headers in packets that match the boolean expression . The headers belonging to protocols like Ethernet , IP , ICMP , UDP and TCP are decoded .
How do I read a pcap file?
Procedure
- Select the event and click the PCAP icon.
- Right-click the PCAP icon for the event and select More Options > View PCAP Information.
- Double-click the event that you want to investigate, and then select PCAP Data > View PCAP Information from the event details toolbar.