I have noticed that if you sniff a subsequent stream from the same server and the first datafile still exists that the second datafile will be named tcpick_ip_ip_clnt.1.dat while the lock file will be named tcpick_ip_ip_clnt.dat. I noticed that during file open in write.c there are 2 calls to avail_filename, one for the data file and one for the lock file and each will return the first available...
2009-04-19 06:25:32 UTC in tcpick: tcp stream tracker and sniffer