yeah, i guess that works, but i should have been more specific
i need to keep a file format so that i can open it in ethereal and do filtering and look through packet headers easier
maybe i am mistaken, because tcpdump -w traffic.log doesn't seem to be capturing the payloads... instead when I open it in ethereal i see "packet size limited during capture"
I am not sure this is the way I want to go though because it could possibly truncate a header, and i need all headers and full headers
Last edited by hedpe; 02-07-2006 at 02:36 PM.