From owner-freebsd-stable@FreeBSD.ORG Tue Nov 18 21:30:40 2008 Return-Path: Delivered-To: stable@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id EA7611065673 for ; Tue, 18 Nov 2008 21:30:40 +0000 (UTC) (envelope-from dudu.meyer@gmail.com) Received: from wf-out-1314.google.com (wf-out-1314.google.com [209.85.200.172]) by mx1.freebsd.org (Postfix) with ESMTP id C00818FC1D for ; Tue, 18 Nov 2008 21:30:40 +0000 (UTC) (envelope-from dudu.meyer@gmail.com) Received: by wf-out-1314.google.com with SMTP id 24so3230971wfg.7 for ; Tue, 18 Nov 2008 13:30:39 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:date:from:to :subject:mime-version:content-type:content-transfer-encoding :content-disposition; bh=pfheWpyScQYNfECQr5JoN/hJbX4OX6Dka1vH5rxKYqg=; b=NfNAA9IpoRI6HU4DfikBmf7IFa8c+I2R08+n3wwWvE+9a7hhSiGHSvjd8Qf5w3itZB WB3tpc11a6H/jffZD8+olNZVEGDurvNk5IdMhsDNsicCGvt9IyJBZLSRQm9kHOEBNY1F d5f6kn++oni16rQgnvfaUQZDTj5hCeiccmJVc= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:to:subject:mime-version:content-type :content-transfer-encoding:content-disposition; b=ZBWOTHeUZmMtGQfQW2iMkohxyZuQLCTldBTWonV67u+JUWI0Fpmf7h1mPLabmVjK27 YBrmzWCQbisBsyXuUL1koWxJ8bpHzPdKL3g1nSSJFPAuzvugCUEPIufUPiKqBgrQ9iV5 XYIqL1y13CwJZF1GBUqxLcDMhNYoVlrHDQtjA= Received: by 10.143.43.7 with SMTP id v7mr132933wfj.192.1227043839841; Tue, 18 Nov 2008 13:30:39 -0800 (PST) Received: by 10.142.229.10 with HTTP; Tue, 18 Nov 2008 13:30:39 -0800 (PST) Message-ID: Date: Tue, 18 Nov 2008 19:30:39 -0200 From: "Eduardo Meyer" To: stable@freebsd.org, questions@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline Cc: Subject: tcpdump(1) filter by date X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 18 Nov 2008 21:30:41 -0000 Hello, I have a kind big tcpdump file, which has data from the last week. I want to dump information based on date. Can I do it without generating a full output and later parse the headers? Say, I want to filter by date in the filter and not with tcpdump -r dumpfile | awk '{ number of packets starting from the epoch-formatted date I have paused my work later. Sometimes I will also need this for pflog files, so, I would appreciate any tips to do this with tcpdump custom files or pflog generated files if there is anything would fit for one situation but not for another. Thank you all in advance. -- =========== Eduardo Meyer pessoal: dudu.meyer@gmail.com profissional: ddm.farmaciap@saude.gov.br