For people asking "do these small tricks/trivia really matter??" I have an example of when they do:
- having strange networking issues on the blue side of a blue/green deployment
- networking engineers are involved
- nobody seems to be able to figure out what's going on despite LOTS of tcpdump/wireshark etc
- I suggest tcpflow[0] (which I used for protocol analysis of chat services etc)
- (there is some skepticism as I was SRE and not networking)
- Turns out that the TCP messages were getting truncated on the problem side
- Networking guys realize the config issue and fix it
I have other examples but this is why it's always good to learn new commands/tools etc.
This, in turn, reminds me of a quote from an army jungle survival expert: "People ask me if it's a good idea to read survival books. I say: 100%. You would be surprised how many people survive an emergency situation because their brain pops out some critical piece of information from a book or article they read 10 years ago."
No to belittle your find even the slightest, but it might be good to notice that tcpflow decodes tcp flows, which is exactly what Wireshark does, only the latter in a GUI and with a plethora of other protocol decoders. Just right click any tcp packet and select Follow.
Both tools even use the same filtering language, coming from tcpdump itself. Wireshark's protocol decoder is more advanced than tcpflow. It does understand fragmented packets. So given a choice, Wireshark is often the preferred tool.
alexpotato · · focus · HN ↗
- having strange networking issues on the blue side of a blue/green deployment
- networking engineers are involved
- nobody seems to be able to figure out what's going on despite LOTS of tcpdump/wireshark etc
- I suggest tcpflow[0] (which I used for protocol analysis of chat services etc)
- (there is some skepticism as I was SRE and not networking)
- Turns out that the TCP messages were getting truncated on the problem side
- Networking guys realize the config issue and fix it
I have other examples but this is why it's always good to learn new commands/tools etc.
This, in turn, reminds me of a quote from an army jungle survival expert: "People ask me if it's a good idea to read survival books. I say: 100%. You would be surprised how many people survive an emergency situation because their brain pops out some critical piece of information from a book or article they read 10 years ago."
0 - <a href="https://linux.die.net/man/1/tcpflow" rel="nofollow">https://linux.die.net/man/1/tcpflow
xorcist · · focus · HN ↗
Both tools even use the same filtering language, coming from tcpdump itself. Wireshark's protocol decoder is more advanced than tcpflow. It does understand fragmented packets. So given a choice, Wireshark is often the preferred tool.