Reputation: 2224
Microsoft-Windows-WinINet-Capture
) from Performance Monitor..etl
file successfully. You can see the payloads with tracerpt FILE_NAME.etl -o FILE_NAME.csv -of CSV
..etl
file contains traffic not only from the target programs but also from other programs like OneNote. So I want to filter the packets with source/destination IP.tracerpt FILE_NAME.etl -o FILE_NAME.csv -of CSV
doesn't have the source IP or destination IP field, so I can't filter the result with Excel..etl
to .pcapng
with pktmon
to read captured packets with WireShark and filter the result, but pktmon
can't read packets from the .etl
file. The result of pktmon
is like this:PS C:\tmp\ETW> pktmon etl2pcap _ETW_CAPTURE_TEST.etl
Processing...
Events lost during logging: 1
Packets total: 0
Packet drop count: 0
Packets formatted: 0
Formatted file: _ETW_CAPTURE_TEST.pcapng
PS C:\tmp\ETW>
Is there any way to filter the packets in a .etl
file from Microsoft-Windows-WinINet-Capture
with the source/destination IP of packets?
Upvotes: 0
Views: 15