Project

General

Profile

Actions

Documentation #4352

open
SB OD

Devguide: Debugging Basics - pcap_cnt

Documentation #4352: Devguide: Debugging Basics - pcap_cnt

Added by Shivani Bhardwaj about 5 years ago. Updated 7 months ago.

Status:
Assigned
Priority:
Low
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

What is pcap_cnt.
How to use it to correlate packet data with Wireshark.
jq commands to check/sort pcap_cnt for particular situations.

SB Updated by Shivani Bhardwaj over 3 years ago Actions #1

  • Assignee changed from Shivani Bhardwaj to Juliana Fajardini Reichow
  • Priority changed from Normal to Low

JF Updated by Juliana Fajardini Reichow over 3 years ago Actions #2

  • Target version set to 8.0.0-beta1

VJ Updated by Victor Julien about 2 years ago Actions #3

  • Assignee changed from Juliana Fajardini Reichow to OISF Dev

VJ Updated by Victor Julien about 1 year ago Actions #4

  • Target version changed from 8.0.0-beta1 to 8.0.0-rc1

VJ Updated by Victor Julien 10 months ago Actions #5

  • Target version changed from 8.0.0-rc1 to 8.0.0

PA Updated by Philippe Antoine 9 months ago Actions #6

  • Target version changed from 8.0.0 to 8.0.1

JL Updated by Jeff Lucovsky 7 months ago Actions #7

 jq -s 'sort_by(.pcap_cnt)' < eve.json

Use this to sort EVE records by pcap_cnt

JL Updated by Jeff Lucovsky 7 months ago Actions #8

This will be more useful if included in the user guide -- eve-json-examples and eve-json-output?

VJ Updated by Victor Julien 7 months ago Actions #9

  • Target version changed from 8.0.1 to 8.0.2

VJ Updated by Victor Julien 7 months ago Actions #10

  • Target version changed from 8.0.2 to 9.0.0-beta1
Actions

Also available in: PDF Atom