sngrep reads a PCAP file with -I, selects a capture interface with -d, writes captured packets to a PCAP with -O, and accepts a BPF filter expression such as 'host 192.168.1.1 and port 5060'.

Checked 2026-09-24

Vendor
Irontec
Product
sngrep
Subsystem
command line
Deployment
on-premises
Region
not restricted
Release range
1.8.x as of 2026-09-24
Checked
2026-09-24

Sources

Cite this note

APA

WarmTransfer. (2026, September 24). SIP capture and analysis with Wireshark and sngrep and HOMER: source note sip-capture-analysis-sngrep-flags. WarmTransfer. https://warmtransfer.net/knowledge/claims/sip-capture-analysis-sngrep-flags

BibTeX

@misc{warmtransfer-claim-sip-capture-analysis-sngrep-flags,
  title  = {SIP capture and analysis with Wireshark and sngrep and HOMER: source note sip-capture-analysis-sngrep-flags},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/sip-capture-analysis-sngrep-flags},
  note   = {Source note sip-capture-analysis-sngrep-flags, checked 2026-09-24}
}

Read in context