On Sun, Mar 29, 2009 at 8:35 PM, Jiri Kuthan <jiri@xxxxxxxxx> wrote: > Why aren't we happy then just with PCAP -- that's a de-facto standard. what does the pcap format give us? see: http://wiki.wireshark.org/Development/LibpcapFileFormat ... it doesn't really solve any of the problems except provide a struct header and record header, much of which we don't even need (and missing stuff we do need). We'd just be shoving whatever formats we defined into a record in them. None of the pcap tools would work on records except raw packets, which most of the time i don't want to be collecting or sending across the network to a collector - a port mirror already does that pretty well :-) ~ Theo _______________________________________________ Sipping mailing list https://www.ietf.org/mailman/listinfo/sipping This list is for NEW development of the application of SIP Use sip-implementors@xxxxxxxxxxxxxxx for questions on current sip Use sip@xxxxxxxx for new developments of core SIP