All Apps and Add-ons

Splunk app for PCAP analyzer - unable to create the csv file by running the script (pcap2csv.sh)

splunker12er
Motivator

OS : MAC
I have installed the app , and as per the steps I dropped a PCAP file(Sample_Traffic.pcap) in the mentioned folder , and tried to execute the script but it gives me the below error.

any thing else i need to consider here? Please help.

That string isn't a valid capture filter (illegal token).
    See the User's Guide for a description of the capture filter syntax.
    Capturing on 'awdl0'
    tshark: Invalid capture filter "–r Sample_Traffic.pcap -T fields -e frame.time -e ip.src -e ip.dst -e _ws.col.Protocol -e tcp.srcport -e tcp.dstport -e tcp.len -e tcp.window_size -e tcp.flags.syn -e tcp.flags.ack -e tcp.flags.push -e tcp.flags.fin -e tcp.flags.reset -e ip.ttl -e _ws.col.Info -e tcp.analysis.ack_rtt -e vlan.id" for interface 'awdl0'!

    That string isn't a valid capture filter (illegal token).
    See the User's Guide for a description of the capture filter syntax.
Tags (2)
0 Karma
1 Solution

kidd452
Engager

hello

I solve the problem.

you can open the shell file,and retype(just delete and type the same) the "tshark -r" for the same string.
I think that is UTF or some binary problem.

View solution in original post

kidd452
Engager

hello

I solve the problem.

you can open the shell file,and retype(just delete and type the same) the "tshark -r" for the same string.
I think that is UTF or some binary problem.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...