Re: [tcpdump-workers] Request for new pcap/pcapng DLT Format

2013-06-13 Thread Guy Harris
On Jun 13, 2013, at 12:07 PM, Guy Harris wrote: > It's not a show-stopper - we can just document them as containing a time > stamp but note that it's redundant with the time stamp in pcap and pcap-ng > files, and say that the time stamp from the pcap packet record header or the > pcap-ng pack

Re: [tcpdump-workers] Request for new pcap/pcapng DLT Format

2013-06-13 Thread Guy Harris
On May 21, 2013, at 1:06 PM, chris_bon...@selinc.com wrote: > Looking at the format again, you are correct - I guess those 8 header bytes > *are* redundant as to what the pcap file has been assigned for the packet > timestamps; I have a feeling they are part of a per-packet direct data dump >

Re: [tcpdump-workers] Request for new pcap/pcapng DLT Format

2013-05-21 Thread Guy Harris
On May 20, 2013, at 7:19 PM, chris_bon...@selinc.com wrote: > I'll include some screen captures of the Comm Monitor interface of the RTAC Just out of curiosity, does that screen shot show a capture made in late November, 2011? If so, was it done in your local area (which appears, from the area

Re: [tcpdump-workers] Request for new pcap/pcapng DLT Format

2013-05-20 Thread Guy Harris
On May 13, 2013, at 1:04 PM, chris_bon...@selinc.com wrote: > 1) The relative timestamp is 8 bytes, the "left" and "right" components > are 32-bit integers representing the left and right-hand side of the > decimal point, respectively Seconds and 1/2^32ths of a second? Speaking of timestamps,

Re: [tcpdump-workers] Request for new pcap/pcapng DLT Format

2013-05-20 Thread Guy Harris
On May 20, 2013, at 6:54 PM, chris_bon...@selinc.com wrote: > Those names sound good to me for the RTAC serial captures. OK, I've assigned 250 for LINKTYPE_RTAC_SERIAL and DLT_RTAC_SERIAL. > After looking a little closer, I suspect that since the RTAC platform is > Linux-based, the programmer

Re: [tcpdump-workers] Request for new pcap/pcapng DLT Format

2013-05-20 Thread chris_bontje
rkers@lists.tcpdump.org Date: 05/20/2013 12:33 PM Subject:Re: [tcpdump-workers] Request for new pcap/pcapng DLT Format On May 13, 2013, at 1:04 PM, chris_bon...@selinc.com wrote: > Hi, I would like to request a custom DLT type for the Schweitzer > Engineering Laboratories &qu

Re: [tcpdump-workers] Request for new pcap/pcapng DLT Format

2013-05-20 Thread Guy Harris
On May 13, 2013, at 1:04 PM, chris_bon...@selinc.com wrote: > Hi, I would like to request a custom DLT type for the Schweitzer > Engineering Laboratories "RTAC" product. Information on the > product/purpose of the DLT is included below: Do LINKTYPE_RTAC_SERIAL/DLT_RTAC_SERIAL sound like good

[tcpdump-workers] Request for new pcap/pcapng DLT Format

2013-05-18 Thread chris_bontje
Hi, I would like to request a custom DLT type for the Schweitzer Engineering Laboratories "RTAC" product. Information on the product/purpose of the DLT is included below: The RTAC product family (SEL-3530, SEL-2241, SEL-3505) is a Linux-based Automation Controller product that is capable of in