Tracing packets in the Linux kernel networking stack and friends
github.com
github.com
> Retis offers many more features including retrieving conntrack information, advanced filtering, monitoring dropped packets and dropped packets from Netfilter, generating pcap files from the collected packets, allowing writing post-processing scripts in Python and more.
Would syntax highlighting be a useful general feature, or should that be a post-processing script in e.g. Python?
Wireshark and also tshark iirc support custom protocol dissectors;
"How can I add a custom protocol analyzer to wireshark?" https://stackoverflow.com/questions/4904991/how-can-i-add-a-...
What can the pcap files contain?
/? ' https://www.google.com/search?q=Can+Wireshark+parse+comments... :
frame.comment contains "Your string"
And there's apparently a way to add a custom column to display frame.comment from pcapng traces in wiresharkThe pcap subcommand, though, will be extended to allow extracting packets from multiple probes in a single run.