diff --git a/salt/common/tools/sbin_jinja/so-import-pcap b/salt/common/tools/sbin_jinja/so-import-pcap index 4169d8769..b8a90421f 100755 --- a/salt/common/tools/sbin_jinja/so-import-pcap +++ b/salt/common/tools/sbin_jinja/so-import-pcap @@ -194,10 +194,6 @@ for PCAP in $INPUT_FILES; do status "- analyzing traffic with Zeek" zeek "${PCAP}" $HASH {% endif %} - - START=$(pcapinfo "${PCAP}" -a |grep "First packet time:" | awk '{print $4}') - END=$(pcapinfo "${PCAP}" -e |grep "Last packet time:" | awk '{print $4}') - status "- saving PCAP data spanning dates $START through $END" fi if [[ "$HASH_FILTERS" == "" ]]; then @@ -208,6 +204,10 @@ for PCAP in $INPUT_FILES; do HASHES="${HASHES} ${HASH}" fi + START=$(pcapinfo "${PCAP}" -a |grep "First packet time:" | awk '{print $4}') + END=$(pcapinfo "${PCAP}" -e |grep "Last packet time:" | awk '{print $4}') + status "- found PCAP data spanning dates $START through $END" + # compare $START to $START_OLDEST START_COMPARE=$(date -d $START +%s) START_OLDEST_COMPARE=$(date -d $START_OLDEST +%s)