I don't know whether this will be applicable to your case, but I've just been analysing some pcap files, and I found the easiest method to be to use Wireshark to export the files as PDML (XML packet detail) and use an XML module to read these. This has the benefit of including all the packet analysis data that Wireshark generates, although PSML may be better if you don't need this.
--
"Any sufficiently analyzed magic is indistinguishable from science" - Agatha Heterodyne
In reply to Re: yet another pcap question
by mykl
in thread yet another pcap question
by Anonymous Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |