High performance packet capturing translator leveraged by gopacket
.
Currently offering JSON packet translation into files and stdout.
Amazing to be used alongside jq
libpcap-dev
: install from distro reposstringer
:go install golang.org/x/tools/cmd/stringer@latest
go generate ./...
go build -o bin/pcap cmd/pcap.go
NOTE: apply
gofumpt
before commit; i/e:gofumpt -l -w .
Using Taskfile
task -v build
task -v dist
task -v docker-build
Using goacket
engine
sudo pcap -eng=google -promisc -i ${IFACE} -s ${SNAPLEN} -fmt=json -stdout -filter='tcp'
sudo pcap -eng=google -promisc -i ${IFACE} -s ${SNAPLEN} -fmt=json -stdout -filter='tcp' -ordered
sudo pcap -eng=google -promisc -i ${IFACE} -s ${SNAPLEN} -w part_%Y%m%d_%H%M%S -ext=json -fmt=json -stdout -filter='tcp'
sudo pcap -eng=google -promisc \
-i ${IFACE} -s ${SNAPLEN} \
-w part_%Y%m%d_%H%M%S -ext=json \
-fmt=json -stdout \
-timeout=60 -filter='tcp'
sudo pcap -eng=google -promisc \
-i ${IFACE} -s ${SNAPLEN} \
-w part_%Y%m%d_%H%M%S -ext=json \
-fmt=json -stdout \
-timeout=60 -interval=10 -filter='tcp'
- Cloud Run tcpdump sidecar: (https://github.com/gchux/cloud-run-tcpdump)
- Plain Text
- Protocol Buffers: https://protobuf.dev/
- gRPC packet capture streaming