NetWitness

Download 61
Last updated Aug 10, 2023

netwitness-packets-batch

Fetch packets from Netwitness Decoder

netwitness-packets-batch profile=PROFILE [pretty=PRETTY]
profile=PROFILE
The identifier of NetWitness connect profile
pretty=PRETTY
t for human readable ASCII output

Output Fields

FieldTypeNameDescription
_timeDateTime
sessionLongSession IDSession ID of NetWitness
src_macStringSource MAC
dst_macStringDestination MAC
src_ipIP addressSource IP
src_portIntegerSource port
dst_ipIP addressDestination IP
dst_portIntegerDestination port
protocolStringProtocol
sizeLongSizeOriginal packet length
payloadBLOBPayloadBinary or hex string
asciiStringASCII viewPayload as ASCII