SQL-like query interface for analyzing PCAP network packet capture files
SQL-like frontend to PCAP files
packetq$ packetq -r capture.pcap 'select src, dst from packets'$ packetq -r capture.pcap 'select src, count(*) from packets where dport=80 group by src'$ packetq -r capture.pcap 'select src, dst, qname from dns'