CentOS 7下Tshark过滤器问题:按时间拆分指定SIP/DIP的PCAP
Hey there! Let's work through this problem you're having—combining IP filtering with time-based PCAP splitting using Tshark, since editcap can't handle the IP criteria directly. I've helped plenty of folks debug Tshark filter mishaps on CentOS 7, so let's break down what's likely going wrong and how to fix it.
Common Filter Mistakes to Check First
Chances are your error stems from one of these super common pitfalls:
- Quotation mark nesting errors: When you include time strings with spaces in your filter, shell parsing can break if you don't quote correctly. For example, writing
-Y "ip.src == 192.168.1.1 and frame.time >= "2024-05-01 00:00:00""tells the shell to end the filter early, leading to invalid syntax. - Incorrect field names: Using non-standard fields like
src_ipinstead ofip.src, ortimeinstead offrame.timewill throw an "invalid filter" error. - Time format/timezone mismatches: If your PCAP uses UTC time but you're filtering with local time, or your time string doesn't match Tshark's expected format, you'll get no results or incorrect matches.
Solution 1: Filter First, Split Second (Simplest & Most Reliable)
Since editcap excels at time splitting, it's often easier to first use Tshark to isolate your target IP traffic, then feed that filtered PCAP to editcap. Here's how:
Step 1: Extract Traffic with Specific SIP/DIP
# Replace the IPs with your target source and destination addresses tshark -r input.pcap -Y 'ip.src == 192.168.1.100 and ip.dst == 10.0.0.5' -w filtered_traffic.pcap
- The single quotes around the filter prevent shell parsing issues with spaces or special characters.
-wwrites the filtered traffic to a new PCAP file we'll use next.
Step 2: Split Filtered PCAP by Time
Use editcap to split the filtered file into chunks (e.g., one file per hour—3600 seconds):
# Split into hourly files, named with timestamp (e.g., split_output_20240501_14.pcap) editcap -i 3600 filtered_traffic.pcap split_output_%Y%m%d_%H.pcap
You can adjust the interval: use 60 for 1-minute chunks, 86400 for daily chunks, etc.
Solution 2: One-Step Tshark Filter + Time Splitting
If you want to do it all in one go (good for scripting), use shell loops with Tshark's epoch time filtering (more reliable than string time formats):
# Example: Split 2024-05-01 traffic into hourly files for your target IPs for hour in {00..23}; do # Define start/end times for the hour start_time="2024-05-01 $hour:00:00" end_time="2024-05-01 $((10#$hour+1)):00:00" # Convert times to Unix epoch timestamps (avoids timezone/format issues) start_epoch=$(date -d "$start_time" +%s) end_epoch=$(date -d "$end_time" +%s) # Run Tshark filter for the IPs + time window, save to a named file tshark -r input.pcap -Y "ip.src == 192.168.1.100 and ip.dst == 10.0.0.5 and frame.time_epoch >= $start_epoch and frame.time_epoch < $end_epoch" -w "output_${start_time// /_}.pcap" done
frame.time_epochuses Unix timestamps (seconds since 1970), so you don't have to worry about matching Tshark's time string format or timezone differences.- The
10#$hourensures leading zeros are handled correctly in arithmetic (e.g.,09becomes9instead of an octal error).
CentOS 7 Specific Notes
CentOS 7 ships with an older Tshark version (usually 1.10.x). If you run into issues with frame.time_epoch, try using ip.time instead (though frame.time_epoch should still work). If you need newer features, you can install a newer Wireshark version via EPEL, but the above commands should work with the default package.
内容的提问来源于stack exchange,提问作者chandu

