Indexing TCP streams within large capture files repository

Title: Indexing TCP streams within large capture files repository
Person: Thomas Maier
Length: 20
Language: Hebrew
Abstract:
My company is using "tcpreplay" as a testing tool.
We're replaying every night hundreds of different capture
files through our devices. The pcap repository includes more
then 1000 files in total size of 1.5TB. When some nasty TCP
stream cause us a headache, we need to find the right pcap
file to reproduce the problem.
The question is not how to find it, but how to find it fast.
Of course with Perl it is an easy job ;-)


 

 

 

 

 

Please send comments, questions etc. to the organizers.