PCAP, short for packet capture, is the standard way captured network traffic is stored and exchanged. The term is used for the capture library itself, for the resulting file, and loosely for the practice of recording traffic. A PCAP file holds the packets as they appeared on the wire, in order, each with a timestamp.
What a PCAP file contains
Each record is one packet, kept whole: the link-layer, IP and transport headers, the payload, and the time it was observed. Nothing is summarised. That is what separates a capture from a metric, and why a PCAP can answer questions nobody thought to ask when it was written.
Two formats are in common use. The original libpcap format is simple and universally supported. The newer pcapng format adds multiple interfaces, comments and higher timestamp resolution, which matters when events are microseconds apart.
How PCAP files are created
At small scale, tcpdump or Wireshark capture directly from a host interface. That is adequate for one machine but misleading for a network, because a host only sees its own traffic and the act of capturing competes with the workload for CPU.
At infrastructure scale, traffic is copied out of the network instead, through a passive tap or a switch mirror port and into a dedicated capture system. The system is then independent of the hosts it observes, which is the point: a server under stress is the least reliable witness to its own behaviour.
Reading and analysing PCAP
PCAP analysis is the examination of those files to establish what happened and when. Wireshark and tshark remain the standard tools, and they work well for a single file that is already known to be interesting.
The difficulty at scale is not reading a file but finding it. When capture runs continuously across many links, the relevant packets sit somewhere inside petabytes, and the practical question becomes whether the capture system can be queried by time, host, protocol or transaction rather than browsed.
Full packet capture and the storage question
Full packet capture means retaining every packet rather than sampling. Sampled approaches such as NetFlow record roughly one packet in thousands, which suits capacity planning and fails for diagnosis, because the packet that caused the problem is almost never the one that was sampled.
The objection to keeping everything is volume, and it is real: a saturated 10Gbps link produces around 4.5TB an hour. Production systems answer it with compression, with retention tiers that hold recent traffic in full and older traffic summarised, and by buffering deeply enough to absorb bursts well above the average rate.
PCAP in trading infrastructure
Electronic trading raises two further requirements: capture has to keep pace with line rate without dropping packets, and timestamps need nanosecond accuracy for the order of events to mean anything. Corvil Network Capture is built for those constraints, and the same record serves both performance work and the regulatory question of what was sent and when.