4 ms·
No to belittle your find even the slightest, but it might be good to notice that tcpflow decodes tcp flows, which is exactly what Wireshark does, only the latte
by xorcist 17d ago
No to belittle your find even the slightest, but it might be good to notice that tcpflow decodes tcp flows, which is exactly what Wireshark does, only the latter in a GUI and with a plethora of other protocol decoders. Just right click any tcp packet and select Follow.
Both tools even use the same filtering language, coming from tcpdump itself. Wireshark's protocol decoder is more advanced than tcpflow. It does understand fragmented packets. So given a choice, Wireshark is often the preferred tool.