Yes, it's called "pktt".
See http://now.netapp.com/NOW/download/tools/capconv/ or http://now.netapp.com/NOW/knowledge/docs/NetCache_Appliance/5.0/html/cmdref/... te6a.htm#1017371 for an example of how to use it.
Steve
-----Original Message----- From: Michael Galloway [mailto:mgx@ornl.gov] Sent: Tuesday, October 17, 2000 9:00 AM To: Toaster Mail Exploder Subject: snoop/tcpdump like tool for ontap?
good day ...
does ontap have a tool like snoop or tcpdump available?
-- michael
Yes, it's called "pktt".
Note that "pktt" merely provides the functionality of "snoop -o" or "tcpdump -w", i.e. it can write a packet trace to a file, but doesn't include any code to display or print a human-readable analysis of the trace.
(It also has a more limited packet-filtering capability than do snoop and tcpdump.)
The capture files are in tcpdump format, so programs that read tcpdump captures, e.g. tcpdump, Ethereal, Analyzer, etc., can read them.
The editcap program that comes with Ethereal can be used to convert capture files in any format that Ethereal can read (it uses the same capture file I/O library that Ethereal and Tethereal use) to any format that Ethereal can write; this lets it write snoop and Microsoft Network Monitor formats, for example.