I plan to use/modify packetbeat as an alternative to wireshark, to analyse huge trace files ( > 10GB) . I have 2 requirements below:
- export data from a pcap capture file
- capture all fields of different protocol layers like mac address, tcp flags etc.
Before getting started, I want to know
- If there is an existing tool that can accomplish this?
- Is this fundamentally against the philosophy of packetbeat/elasticsearch ?
Thanks in advance,