packetq is a command line tool to run SQL queries directly on PCAP files, the results can be outputted as JSON (default), formatted/compact CSV and XML. It also contain a very simplistic web-server in order to inspect PCAP files remotely. PacketQ was previously known as DNS2db but was renamed in 2011 when it was rebuilt and could handle protocols other than DNS among other things.
A short demo-video of PacketQ's capabilities is available on http://www.youtube.com/watch?v=70wJmWZE9tY
Packages for Debian, Ubuntu and RPM (CentOS, Fedora, RHEL, SLE and openSUSE) can be found here: https://dev.dns-oarc.net/packages/
Here are the releases of PacketQ with the latest at the top, read about the changes in the changelog.
|packetq-1.4.2.tar.gz||Mar 2, 2020||917K|
|packetq-1.4.1.tar.gz||Nov 9, 2017||917K|
|packetq-1.4.0.tar.gz||Jul 11, 2017||914K|
|packetq-1.3.1.tar.gz||Jun 02, 2017||913K|
|packetq-1.3.0.tar.gz||May 23, 2017||912K|
You can clone the code repositories from GitHub:
$ git clone https://github.com/DNS-OARC/PacketQ.git