SATO Yusuke
SATO Yusuke

Reputation: 2224

Filter the .etl from Microsoft-Windows-WinINet-Capture with source/destination IP

Background

Problem

PS C:\tmp\ETW> pktmon etl2pcap _ETW_CAPTURE_TEST.etl
Processing...

Events lost during logging: 1
Packets total:       0
Packet drop count:   0
Packets formatted:   0
Formatted file:      _ETW_CAPTURE_TEST.pcapng
PS C:\tmp\ETW>

Question

Is there any way to filter the packets in a .etl file from Microsoft-Windows-WinINet-Capture with the source/destination IP of packets?

Upvotes: 0

Views: 15

Answers (0)

Related Questions