DuckDB PCAP Extension
August 25, 2025 ยท View on GitHub
A DuckDB extension for reading PCAP (packet capture) files directly in SQL queries.
Installation
git clone --recurse-submodules https://github.com/yourusername/duckdb_pcap.git
cd duckdb_pcap
make configure
make release
Usage
-- Load the extension
LOAD 'build/release/duckdb_pcap.duckdb_extension';
-- Query packets from a PCAP file
SELECT * FROM read_pcap('capture.pcap');
-- Analyze network traffic
SELECT
COUNT(*) as total_packets,
MIN(timestamp_ns) / 1e9 as start_time,
MAX(timestamp_ns) / 1e9 as end_time,
SUM(capture_len) as total_bytes
FROM read_pcap('network.pcap');
Schema
The read_pcap() function returns:
timestamp_ns(UBIGINT): Packet timestamp in nanosecondsoriginal_len(UINTEGER): Original packet lengthcapture_len(UINTEGER): Captured packet lengthdata(BLOB): Raw packet data
Building
# Setup
make configure
# Build
make debug # Debug build
make release # Release build
# Clean
make clean # Clean build artifacts
make clean_all # Clean everything
Testing
make test_debug # Test debug build
make test_release # Test release build
Requirements
- C/C++ compiler
- CMake
- Make
- Python 3 (for testing)
PCAP Format
This extension supports the PCAP format as specified in draft-gharris-opsawg-pcap-01.