Re: [tcpdump-workers] Are all traces captured by dag card in "tcpdump"

2004-06-04 Thread ice ice
traces captured by dag card in "tcpdump" Date: Fri, 4 Jun 2004 11:33:51 -0700 On Jun 4, 2004, at 9:32 AM, ice ice wrote: Yes, I should say that the trace file is in pcap format. 20020814-09-0-anon.pcap.gz: tcpdump capture file (little-endian) - version 2.4 (BSD/OS Cisco HDLC, cap

Re: [tcpdump-workers] Are all traces captured by dag card in "tcpdump"

2004-06-04 Thread ice ice
From: Stephen Donnelly <[EMAIL PROTECTED]> Reply-To: [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: Re: [tcpdump-workers] Are all traces captured by dag card in "tcpdump" Date: Fri, 04 Jun 2004 14:45:25 +1200 ice ice wrote: I have a trace saying "Data provided by WAND Re

[tcpdump-workers] Are all traces captured by dag card in "tcpdump" format?

2004-06-03 Thread ice ice
Hi, I have a trace saying "Data provided by WAND Research Group using the dag interface card OC48 data analysis required CAIDA's CoralReef software suite." I am confused by the statement of "OC48 data analysis required CAIDA's CoralReef software suite". It seems to me that traces captured by dag

[tcpdump-workers] why processing large trace file is very slow?

2004-04-28 Thread ice ice
Hi, I have been using tcpdump analyzing trace files. Recently I try to analyze some big trace files of several hundreds Mbs to more than 2GB. I am not sure why the tcpdump is so slow in processing the file, just a simple command: tcpdump -c 100 -r trace > output takes tens of minutes to finish. A