4 capinfos - Prints information about binary capture files
25 B<Capinfos> is a program that reads one or more saved capture files and
26 returns any or all of several statistics about each file. B<Capinfos> is
27 able to detect and read any capture supported by the B<Ethereal> package.
29 B<Capinfos> can read the following file formats:
34 libpcap/WinPcap, tcpdump and various other tools using tcpdump's capture format
37 B<snoop> and B<atmsnoop>
40 Shomiti/Finisar B<Surveyor> captures
43 Novell B<LANalyzer> captures
46 Microsoft B<Network Monitor> captures
49 AIX's B<iptrace> captures
52 Cinco Networks B<NetXRay> captures
55 Network Associates Windows-based B<Sniffer> captures
58 Network General/Network Associates DOS-based B<Sniffer> (compressed or uncompressed) captures
61 AG Group/WildPackets B<EtherPeek>/B<TokenPeek>/B<AiroPeek>/B<EtherHelp>/B<PacketGrabber> captures
64 B<RADCOM>'s WAN/LAN analyzer captures
67 Network Instruments B<Observer> version 9 captures
70 B<Lucent/Ascend> router debug output
73 files from HP-UX's B<nettl>
76 B<Toshiba's> ISDN routers dump output
79 the output from B<i4btrace> from the ISDN4BSD project
82 traces from the B<EyeSDN> USB S0.
85 the output in B<IPLog> format from the Cisco Secure Intrusion Detection System
88 B<pppd logs> (pppdump format)
91 the output from VMS's B<TCPIPtrace>/B<TCPtrace>/B<UCX$TRACE> utilities
94 the text output from the B<DBS Etherwatch> VMS utility
97 Visual Networks' B<Visual UpTime> traffic capture
100 the output from B<CoSine> L2 debug
103 the output from Accellent's B<5Views> LAN agents
106 Endace Measurement Systems' ERF format captures
109 Linux Bluez Bluetooth stack B<hcidump -w> traces
113 There is no need to tell B<Capinfos> what type of
114 file you are reading; it will determine the file type by itself.
115 B<Capinfos> is also capable of reading any of these file formats if they
116 are compressed using gzip. B<Capinfos> recognizes this directly from the
117 file; the '.gz' extension is not required for this purpose.
119 The user specifies which statistics to report by specifying flags
120 corresponding to the statistic. If no flags are specified, B<Capinfos> will
121 report all statistics available.
129 Displays the capture type of the capture file.
133 Counts the number of packets in the capture file.
137 Displays the size of the file, in bytes. This reports
138 the size of the capture file itself.
142 Displays the total length of all packets in the file, in
143 bytes. This counts the size of the packets as they appeared
144 in their original form, not as they appear in this file.
145 For example, if a packet was originally 1514 bytes and only
146 256 of those bytes were saved to the capture file (if packets
147 were captured with a snaplen or other slicing option),
148 B<Capinfos> will consider the packet to have been 1514 bytes.
152 Displays the capture duration, in seconds. This is the
153 difference in time between the earliest packet seen and
158 Displays the start time of the capture. B<Capinfos> considers
159 the earliest timestamp seen to be the start time, so the
160 first packet in the capture is not necessarily the earliest -
161 if packets exist "out-of-order", time-wise, in the capture,
162 B<Capinfos> detects this.
166 Displays the end time of the capture. B<Capinfos> considers
167 the latest timestamp seen to be the end time, so the
168 last packet in the capture is not necessarily the latest -
169 if packets exist "out-of-order", time-wise, in the capture,
170 B<Capinfos> detects this.
174 Displays the average data rate, in bytes
178 Displays the average data rate, in bits
182 displays the average packet size, in bytes
186 Prints the help listing and exits.
192 I<tcpdump(8)>, I<pcap(3)>, I<ethereal(1)>, I<mergecap(1)>, I<editcap(1)>, I<tethereal(1)>
196 B<Capinfos> is part of the B<Ethereal> distribution. The latest version
197 of B<Ethereal> can be found at B<http://www.ethereal.com>.
203 Ian Schorr <ian[AT]ianschorr.com>
208 Gerald Combs <gerald[AT]ethereal.com>