pcap2json
pcap2json copied to clipboard
Getting "Unknown command line option" when using the pcap2json utility
Hi,
Need help in execution of the below command line to Upload packet data directly into Elastic stack. Getting "Unknown command line option" when using the pcap2json utility.
I have cloned the project on a Ubuntu 20.04 VM. and used make command to build the pcap2json utility. Let me know if anything is amiss.
root@es7:~/pcap2json# cat /etc/os-release NAME="Ubuntu" VERSION="20.04.3 LTS (Focal Fossa)" ID=ubuntu ID_LIKE=debian PRETTY_NAME="Ubuntu 20.04.3 LTS" VERSION_ID="20.04" HOME_URL="https://www.ubuntu.com/" SUPPORT_URL="https://help.ubuntu.com/" BUG_REPORT_URL="https://bugs.launchpad.net/ubuntu/" PRIVACY_POLICY_URL="https://www.ubuntu.com/legal/terms-and-policies/privacy-policy" VERSION_CODENAME=focal UBUNTU_CODENAME=focal
root@es7:~/pcap2json# cat /home/student/ELK/http.cap | ./pcap2json --json-packet --capture-name http --output-espush --es-compress --es-host 192.168.1.248:9200 pcap2json https://www.github/fmadio/pcap2json build:Mar 31 2023 06:07:57 [--json-packet] Write JSON Packet meta data [--capture-name] Unknown command line option [--capture-name] root@es7:~/pcap2json# cat /home/student/ELK/http.cap | ./pcap2json --json-packet --output-espush --es-compress --es-host 192.168.1.248:9200 pcap2json https://www.github/fmadio/pcap2json build:Mar 31 2023 06:07:57 [--json-packet] Write JSON Packet meta data [--output-espush] Unknown command line option [--output-espush] root@es7:~/pcap2json# cat /home/student/ELK/http.cap | ./pcap2json --json-packet --es-compress --es-host 192.168.1.248:9200 pcap2json https://www.github/fmadio/pcap2json build:Mar 31 2023 06:07:57 [--json-packet] Write JSON Packet meta data [--es-compress] Unknown command line option [--es-compress] root@es7:~/pcap2json# cat /home/student/ELK/http.cap | ./pcap2json --json-packet --es-host 192.168.1.248:9200 pcap2json https://www.github/fmadio/pcap2json build:Mar 31 2023 06:07:57 [--json-packet] Write JSON Packet meta data [--es-host] Unknown command line option [--es-host] root@es7:~/pcap2json# ./pcap2json --help pcap2json https://www.github/fmadio/pcap2json build:Mar 31 2023 06:07:57 [--help] fmad engineering all rights reserved http://www.fmad.io
pcap2json is a high speed PCAP meta data extraction utility
example converting a pcap to json:
cat /tmp/test.pcap | pcap2json > test.json
Command Line Arguments:
--index-name
--cpu-core
--json-packet : write JSON packet data --json-flow : write JSON flow data
Instance Info
--instance-id : instance id of this pcap2json FE
--instance-max : total number of pcap2json FE instances
Output Mode
--output-stdout : writes output to STDOUT
--output-espush : writes output directly to ES HTTP POST
--output-histogram
Flow specific options
--flow-samplerate
Elastic Stack options
--es-host hostname:port : Sets the ES Hostname
--es-timeout
ICMP options --icmp-overwrite : overwrite IP Proto info for ICMP packets