interface PcapRecord

Decoded representation of a single pcap record.

inclLen is the number of bytes actually stored on disk and read into data; origLen is the original wire length, which can be greater when the capture was truncated by snapLen.

Properties

tsSec: number

Timestamp seconds since the Unix epoch.

tsUsec: number

Sub-second portion of the timestamp.

Microseconds for files using PCAP_MAGIC_MICROS, nanoseconds for those using PCAP_MAGIC_NANOS. The pcap layout reuses the same field name for both, so the interpretation is dictated entirely by the global header magic.

inclLen: number

Number of bytes of packet data actually present in data.

origLen: number

Original packet length on the wire (may exceed inclLen).

Captured packet payload, exactly inclLen bytes long.

Usage

import { type PcapRecord } from ".";