NTAR: Network Trace Archival and Retrieval Library

Welcome to the NTAR website, the Network Trace Archival and Retrieval library. The main objective of NTAR is to provide an extensible way to store and retrieve network traces to mass storage. The NTAR file format includes support for saving a number of per-capture and per-packet details ("metadata") in a simple and yet powerful manner.

NTAR implements a new "wanna-be" dump standard that overcomes the limits of the current libpcap/WinPcap dump format, by allowing the user to save packets coming from multiple interfaces and different data-links in a single trace file. More information on this new trace format can be found in PCAP Next Generation Dump File Format.

NTAR is a fresh project looking for contributors. If you want to be among them, you can join the ntar-workers [at] winpcap.org mailing list. At the moment, NTAR is available in source code format only, from the download page. In the future, we plan to set up a public CVS repository.

WinPcap Enhancements

Riverbed FORCE

Riverbed FORCE

Riverbed FORCE offers three full days of deep technical training on hybrid architectures and solutions in performance management, WAN optimization, branch converged infrastructure, application delivery, and cloud storage delivery.

Register Today

AirPcap®: 802.11 Wireless Packet Capture Device

AirPcap

  • View management, control and data frames in Wireshark
  • Plug & play 802.11 a/b/g/n capture
  • Multi-channel aggregation
  • USB form factor

Learn More »

TurboCap Gigabit Capture Card

TurboCap
  • Full-speed GigE capture and injection
  • Port aggregation
  • Pass-thru mode
  • Aggregating tap
  • Exported interfaces
  • TurboCap API developer's pack
  • Sample applications like "dump-to-disk" for high-speed capture to disk

Learn More »