Suricata Error while processing PCAP

Hi, I am trying to process a large pcap file (~30 GB), but it throws this error:

- [ERRCODE: SC_ERR_PCAP_OPEN_OFFLINE(26)] - failed to get first packet timestamp. pcap_next_ex(): -1

I was told this pcap file was merged from multiple small ones, I don’t know if that could create any problems.

Hi,

It is possible that the pcap file has a problem because of what you mention. You can use to repair it:

pcapfix