Use a python program to split the file up. Pcaps are easy to parse with
struct.
Rob MacKenzie
Test Software Developer
-----Original Message-----
From: wireshark-users-bounces@xxxxxxxxxxxxx
[mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of miguel
olivares varela
Sent: May 13, 2008 10:08 AM
To: wireshark-users@xxxxxxxxxxxxx
Subject: [Wireshark-users] tshark error
Hi
I got the latest version of wireshark 1.0.0 over linux centos 5.1, i
try to analyze a pcap file aboout 3Gb with tshark but when i type the
following command i got an error message,
# tshark -r capture2.pcap -qz io,stat,1>>bw.out
Running as user "root" and group "root". This could be dangerous.
tshark: The file "capture2.pcap" could not be opened: Too large value
for the definite type of data.
does anybody knows why?
thanks
_________________________________________________________________
Discover the new Windows Vista
http://search.msn.com/results.aspx?q=windows+vista&mkt=en-US&form=QBRE
_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
http://www.wireshark.org/mailman/listinfo/wireshark-users
---------------------------------------------------------------------
This transmission (including any attachments) may contain confidential information, privileged material (including material protected by the solicitor-client or other applicable privileges), or constitute non-public information. Any use of this information by anyone other than the intended recipient is prohibited. If you have received this transmission in error, please immediately reply to the sender and delete this information from your system. Use, dissemination, distribution, or reproduction of this transmission by unintended recipients is not authorized and may be unlawful.