CICFlowMeter
CICFlowMeter copied to clipboard
Convert UNSW-NB15 pcaps
Hi All,
I am trying to convert the UNSW-NB15 dataset pcaps using the CICFlowMeter. It would load all the pcaps fine, however, it says it has not found any valid flows and discards the whole pcap.
Any ideas why?
Tried on another dataset pcaps and worked fine.
Thanks.
@msarhan95 you can process it with NFStream.
Github Repository: https://github.com/nfstream/nfstream
If you don't receive any output probably the problem is from your pcap file. If the pcap files don't have an ethernet layer the CICFlowmeter can't detect any flows. You need to add the ethernet layer to all pcap files, and it will work. tcprewrite --dlt=enet --infile="" --outfile=""