Merging and splitting PCAP data

Sometimes, for a particular timeframe, we need to merge the captured data. This eliminates analyses on different PCAP files, and after merging, we have only a single file to work with. In Wireshark, we can combine various PCAP files through the Merge... option, as shown in the following screenshot:

Using the Merge... option from the File menu, we can merge other files:

In the preceding screenshot, we have a final_show-01.cap file open in Wireshark and select the Merge option from the File menu, and we select  ...

Get Hands-On Network Forensics now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.