<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recent changes to PCAPRUNNER</title><link>https://sourceforge.net/p/pcaprunner/wiki/PCAPRUNNER/</link><description>Recent changes to PCAPRUNNER</description><atom:link href="https://sourceforge.net/p/pcaprunner/wiki/PCAPRUNNER/feed" rel="self"/><language>en</language><lastBuildDate>Sun, 14 Apr 2019 16:06:32 -0000</lastBuildDate><atom:link href="https://sourceforge.net/p/pcaprunner/wiki/PCAPRUNNER/feed" rel="self" type="application/rss+xml"/><item><title>PCAPRUNNER modified by Markus Thilo</title><link>https://sourceforge.net/p/pcaprunner/wiki/PCAPRUNNER/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v16
+++ v17
@@ -36,7 +36,7 @@
 `pcaprunner -s -r -c -w outfile.pcnf dump1.pcap dump2.pcap` = writes statistic data to file and gives infos about single IP addresses on stdout

 # Development and License:
-The use, development, distribution, etc. of the script is subject to the restrictions of GPL Version 3. The tools are in alpha state. The developer is not responsible for the use of the tools. Accuracy is not garanteed. You are welcome to participate or donate to the development. Feel free to report bugs or give suggestions by email to:
+The use, development, distribution, etc. of the script is subject to the restrictions of GPL Version 3. The tools are in beta state. The developer is not responsible for the use of the tools. Accuracy is not garanteed. You are welcome to participate or donate to the development. Feel free to report bugs or give suggestions by email to:

 markus.thilo@gmail.com

&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Markus Thilo</dc:creator><pubDate>Sun, 14 Apr 2019 16:06:32 -0000</pubDate><guid>https://sourceforge.net05ffddf396c036e481915561a1572648190ebbd5</guid></item><item><title>PCAPRUNNER modified by Markus Thilo</title><link>https://sourceforge.net/p/pcaprunner/wiki/PCAPRUNNER/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v15
+++ v16
@@ -4,7 +4,7 @@
 PCAPRUNNER uses only the C standard library, no LIBPCAP..

 # Compile:
-`gcc -o pcaprunner pcaprunner_vX.Y.c` or use `$ make`.
+`gcc -o pcaprunner pcaprunner_vX.Y.c` or use `make`.

 The programm is written on a Linux / x86_64 based system. It had also been ported to Windows using mingw-w64-gcc, so you can use `pcaprunner.exe` or the GUI `pcaprunner_gui.exe`.

&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Markus Thilo</dc:creator><pubDate>Sun, 14 Apr 2019 16:04:20 -0000</pubDate><guid>https://sourceforge.net3a0a1c485d802e8de0c788b7075bd5f7123f6cde</guid></item><item><title>PCAPRUNNER modified by Markus Thilo</title><link>https://sourceforge.net/p/pcaprunner/wiki/PCAPRUNNER/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v14
+++ v15
@@ -1,5 +1,5 @@
 # PCAPRUNNER
-PCAPRUNNER is a command lione tool that runs through PCAP files and statistically analyzes IP packets. Other packets are ignored. Adresses, ports, oldest timestamp, youngest timestamp (first seen / last seen), the quantity of packets and the sum of the packet volumes (as given in the PCAP file as orig_len) are listed.
+PCAPRUNNER is a command line tool that runs through PCAP files and statistically analyzes IP packets. Other packets are ignored. Adresses, ports, oldest timestamp, youngest timestamp (first seen / last seen), the quantity of packets and the sum of the packet volumes (as given in the PCAP file as orig_len) are listed.

 PCAPRUNNER uses only the C standard library, no LIBPCAP..

&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Markus Thilo</dc:creator><pubDate>Sun, 14 Apr 2019 16:03:29 -0000</pubDate><guid>https://sourceforge.net8dff9d30cbe8097bd6421031d96603a32631b5e0</guid></item><item><title>PCAPRUNNER modified by Markus Thilo</title><link>https://sourceforge.net/p/pcaprunner/wiki/PCAPRUNNER/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v13
+++ v14
@@ -6,7 +6,7 @@
 # Compile:
 `gcc -o pcaprunner pcaprunner_vX.Y.c` or use `$ make`.

-The programm is written on a Linux / x86_64 based system. It had also been ported to Windows using mingw-w64-gcc, so you can use `pcaprunner.exe`.
+The programm is written on a Linux / x86_64 based system. It had also been ported to Windows using mingw-w64-gcc, so you can use `pcaprunner.exe` or the GUI `pcaprunner_gui.exe`.

 # Usage:

&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Markus Thilo</dc:creator><pubDate>Wed, 21 Nov 2018 13:28:57 -0000</pubDate><guid>https://sourceforge.nete40c92f6d1ffd8ecf9827e72f05692591bbc7c70</guid></item><item><title>PCAPRUNNER modified by Markus Thilo</title><link>https://sourceforge.net/p/pcaprunner/wiki/PCAPRUNNER/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v12
+++ v13
@@ -6,7 +6,7 @@
 # Compile:
 `gcc -o pcaprunner pcaprunner_vX.Y.c` or use `$ make`.

-The programm is written on a Linux / x86_64 based system. It had also be ported to Windows using mingw-w64-gcc, so you can use `pcaprunner.exe`.
+The programm is written on a Linux / x86_64 based system. It had also been ported to Windows using mingw-w64-gcc, so you can use `pcaprunner.exe`.

 # Usage:

&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Markus Thilo</dc:creator><pubDate>Tue, 30 Oct 2018 22:35:43 -0000</pubDate><guid>https://sourceforge.net49cc2233afc0c5d0c23166093102384f43841769</guid></item><item><title>PCAPRUNNER modified by Markus Thilo</title><link>https://sourceforge.net/p/pcaprunner/wiki/PCAPRUNNER/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v11
+++ v12
@@ -6,7 +6,7 @@
 # Compile:
 `gcc -o pcaprunner pcaprunner_vX.Y.c` or use `$ make`.

-The programm is written on a Linux / x86_64 based system. It had also be ported to Windows so pcaprunner.exe can be build using mingw-w64-gcc.
+The programm is written on a Linux / x86_64 based system. It had also be ported to Windows using mingw-w64-gcc, so you can use `pcaprunner.exe`.

 # Usage:

&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Markus Thilo</dc:creator><pubDate>Tue, 30 Oct 2018 22:34:09 -0000</pubDate><guid>https://sourceforge.netf267c96944a62362ed222c718fae232dbc54ed52</guid></item><item><title>PCAPRUNNER modified by Markus Thilo</title><link>https://sourceforge.net/p/pcaprunner/wiki/PCAPRUNNER/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v10
+++ v11
@@ -4,9 +4,9 @@
 PCAPRUNNER uses only the C standard library, no LIBPCAP..

 # Compile:
-`gcc -o pcaprunner pcaprunner_vX.Y.c`
+`gcc -o pcaprunner pcaprunner_vX.Y.c` or use `$ make`.

-The programm is written on a Linux / x86_64based system,
+The programm is written on a Linux / x86_64 based system. It had also be ported to Windows so pcaprunner.exe can be build using mingw-w64-gcc.

 # Usage:

&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Markus Thilo</dc:creator><pubDate>Tue, 30 Oct 2018 22:32:43 -0000</pubDate><guid>https://sourceforge.net8a30677a18d8892ac5649f456a98c255ec301ce2</guid></item><item><title>PCAPRUNNER modified by Markus Thilo</title><link>https://sourceforge.net/p/pcaprunner/wiki/PCAPRUNNER/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v9
+++ v10
@@ -19,7 +19,7 @@
 * --help, -h
 * -r   Print timestamps and traffic volumes in human readable format. The time stamps are taken from the PCAP files without any validation or adjustment.
 * -s   Print statistics about single addresses (default if not -w or -j). The list starts with the address of largest traffic volume. In most scenarios this should be the observed address.
-* -l   Print statistics about links (traffica from source to destination address). 
+* -l   Print statistics about links (traffic from source to destination address). 
 * -b   Print statistics about bidirectional links (traffic inbetween addresses, both directions).
 * -p   Print statistics about ports per address (one address, one port).
 * -v   Verbose print netflow data. This will give the traffic inbetween same addresses and ports (logical "and" = "&amp;amp;&amp;amp;" - this is the most differentiated statistic).
@@ -27,7 +27,7 @@
 *  -a DELIMITER    Sets the delimiter character inbetween IP address and port number. Default is ':'.
 *  -d DELIMITER    Sets the delimiter character inbetween other data. Default is tab stop.
 *  -w PCNF-FILE    Write output to file. The file format is PCNF. You should name it 'FILENAME.pcnf'. PCNF is the native binary file format. It is effective for large PCAP files to do this first.
-*  -j JSON-FILE Write output to file. The file format is JSON. You should name it 'FILENAME.json'.
+*  -j JSON-FILE Write output to file. The file format is JSON. You should name it 'FILENAME.json'. You might use Python ore some other laguage to use the data.

 Only one statistic / output at a time. Best choice for big data is to use -w on the first run. Example: pcaprunner -w neflow.pcnf dump1.pcap dump2.pcap

&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Markus Thilo</dc:creator><pubDate>Thu, 25 Oct 2018 21:14:26 -0000</pubDate><guid>https://sourceforge.netfc53b9941f23a555c6486c83b247feb53e879f78</guid></item><item><title>PCAPRUNNER modified by Markus Thilo</title><link>https://sourceforge.net/p/pcaprunner/wiki/PCAPRUNNER/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v8
+++ v9
@@ -6,7 +6,7 @@
 # Compile:
 `gcc -o pcaprunner pcaprunner_vX.Y.c`

-The programm is written on a Lunux / x86_64based system,
+The programm is written on a Linux / x86_64based system,

 # Usage:

@@ -31,6 +31,10 @@

 Only one statistic / output at a time. Best choice for big data is to use -w on the first run. Example: pcaprunner -w neflow.pcnf dump1.pcap dump2.pcap

+# Example:
+
+`pcaprunner -s -r -c -w outfile.pcnf dump1.pcap dump2.pcap` = writes statistic data to file and gives infos about single IP addresses on stdout
+
 # Development and License:
 The use, development, distribution, etc. of the script is subject to the restrictions of GPL Version 3. The tools are in alpha state. The developer is not responsible for the use of the tools. Accuracy is not garanteed. You are welcome to participate or donate to the development. Feel free to report bugs or give suggestions by email to:

&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Markus Thilo</dc:creator><pubDate>Wed, 24 Oct 2018 14:15:49 -0000</pubDate><guid>https://sourceforge.netae6664c717c293276a9b87b19f663196307f6228</guid></item><item><title>PCAPRUNNER modified by Markus Thilo</title><link>https://sourceforge.net/p/pcaprunner/wiki/PCAPRUNNER/</link><description>&lt;div class="markdown_content"&gt;&lt;pre&gt;--- v7
+++ v8
@@ -24,7 +24,7 @@
 * -p   Print statistics about ports per address (one address, one port).
 * -v   Verbose print netflow data. This will give the traffic inbetween same addresses and ports (logical "and" = "&amp;amp;&amp;amp;" - this is the most differentiated statistic).
 * -c   Print a head line with the meaning of the columns as first line before the data sets.
-*  -a DELIMITER    Sets the delimiter character inbetween IP address and port number. Default is ':'..
+*  -a DELIMITER    Sets the delimiter character inbetween IP address and port number. Default is ':'.
 *  -d DELIMITER    Sets the delimiter character inbetween other data. Default is tab stop.
 *  -w PCNF-FILE    Write output to file. The file format is PCNF. You should name it 'FILENAME.pcnf'. PCNF is the native binary file format. It is effective for large PCAP files to do this first.
 *  -j JSON-FILE Write output to file. The file format is JSON. You should name it 'FILENAME.json'.
&lt;/pre&gt;
&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Markus Thilo</dc:creator><pubDate>Mon, 22 Oct 2018 06:43:21 -0000</pubDate><guid>https://sourceforge.net7f5ae6e17588156a1cc3606d5bd977da314ed6a0</guid></item></channel></rss>