Thursday 28 May 2009

How to convert snoop output to read in Ethereal

Snoop to a file in Solaris
# snoop -o test.snoopraw

Transfer your file in binary mode to your windows machine.
under your wireshark installation folder find editcap application and convert your file to wireshark
"D:\Program Files\Wireshark\editcap.exe" "d:\testsnoopraw" "d:\testsnoopraw.snoop"

No comments: