data:image/s3,"s3://crabby-images/25e93/25e93b0d625dae36911be7e60ac57a79bbb33350" alt="Split wireshark pcap file"
data:image/s3,"s3://crabby-images/6ac9b/6ac9b38ff99ce168e624d04a6598e05bc3509b80" alt="split wireshark pcap file split wireshark pcap file"
“C:datasetsdataset.pcap” is the path to input file and “C:datasetsanondataset-split-.pcap” contains the path and the name template of the output files. The option -c 300000 defines the maximum amount of packets in a single output file. Since editcap lacks a GUI, we need to use Windows Command Prompt interface.įirst, we need to change directory to Wireshark’s installation directory where editcap is located, by default it is C:Program FilesWireshark: cd "C:Program FilesWireshark"Ī typical Windows command to split a file using editcap looks something like this: editcap -c 300000 "C:datasetsdataset.pcap" "C:datasetsanondataset-split-.pcap" To split up PCAP files we use Wireshark’s editcap feature. Since a typical network traffic dataset usually consists of PCAP/pcapng files that are several gigabytes in size, you will need to split the files in question into smaller, more digestible chunks. First of all, the maximum size of a file that TraceWrangler can open is 2 GB. TraceWrangler is very easy to use and has an intuitive GUI:
data:image/s3,"s3://crabby-images/c4ec4/c4ec45b326c1a17c9ae97b9ae3126910d2c8d655" alt="split wireshark pcap file split wireshark pcap file"
We use TraceWrangler for network data anonymization on OSI Layers 2 through 4. In order to not reveal your network infrastructure and/or other sensitive data, you must anonymize these files before sharing them with anyone outside of you organization.
data:image/s3,"s3://crabby-images/5f04f/5f04f98c44a743500f7879b889bb235587699504" alt="split wireshark pcap file split wireshark pcap file"
Sometimes you may need to provide PCAP files to third-party organizations or perhaps, in our case, publish a network traffic dataset. Network traffic dataset PCAP anonymization
data:image/s3,"s3://crabby-images/25e93/25e93b0d625dae36911be7e60ac57a79bbb33350" alt="Split wireshark pcap file"