Writing a packet trace in Sniffer format to a data set
Use the following procedure to write a packet trace in Network Associates Sniffer format to a data set. The file can then be used as input to Wireshark.
Before you begin
You must preallocate a data set before you begin writing a packet trace to a data set in Sniffer format. This process is not performed within the program. The packet data set attributes must be as follows:
- Organization: PS
- Record format: VB
- Record Length: 1600
- Block Size: 27998
For more information, see the MainView for IP Customization Guide.
To write a packet trace in Sniffer format to a data set
- From the EZIP menu select Packet Tracing from the Diagnostics section, and press Enter.
- In the Command field of the packet tracing view (PKTTRACE), type SNIFF, and press Enter.
Type the name of the data set in the File Name field, and any other types of filters that you want, and press Enter.
- Press F3 or type END to complete the task.A message is displayed that confirms the packet trace is being written to the specified data set.
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*