Skip to content

Feature request: support netsh trace start provider=Microsoft-Windows-TCPIP #84

@kgibm

Description

@kgibm

In some cases, Microsoft support has requested netsh trace start provider=Microsoft-Windows-TCPIP; however, etl2pcapng currently doesn't support this GUID 2f07e2ee-15db-40f1-90ef-9d7ba282188a and causes the error Input ETL file does not contain an ndiscap packet capture. Such an ETL can be converted to text with netsh trace convert and it seems to have all the data we'd normally expect in Wireshark, but it is in a proprietary text format rather than pcap.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions