# Install ipsumdump with Homebrew

Summarizes TCP/IP dump files into a self-describing ASCII format. Version 1.86 via Homebrew; verified from local package data.

## Install

```sh
sudo av install brew:ipsumdump
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install ipsumdump
```

  Evidence: local Homebrew formula metadata

## Package facts

- **Package key:** brew:ipsumdump
- **Package manager:** Homebrew
- **Version:** 1.86
- **Source summary:** Summarizes TCP/IP dump files into a self-describing ASCII format
- **Homepage:** <https://read.seas.harvard.edu/~kohler/ipsumdump/>
- **Repository:** <https://github.com/kohler/ipsumdump>
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- ipaggcreate (alias)
- ipaggmanip (alias)
- ipsumdump (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 1.86
## Project history and usage

ipsumdump is Eddie Kohler's packet-trace summarizer: it reads live interfaces, tcpdump/pcap files, NetFlow summaries, DAG/NLANR traces, or prior ipsumdump files and emits a self-describing ASCII packet summary.

### Project history

The project page presents ipsumdump as a traffic-analysis tool built around IP summary dumps: line-oriented output that is easy for people and scripts to process. Its companion ipaggcreate counts packet aggregates, making the package useful for trace-analysis questions such as flow-size distributions and address-discovery timing.

ipsumdump is historically tied to the Click modular router. The project page calls it the first standalone program to use Click, explains that ipsumdump builds a Click configuration from command-line options, and notes that elements written for ipsumdump were fed back into Click for other projects.

### Adoption history

The project appears to have remained a specialist research and network-measurement tool rather than a broadly adopted admin command. Its news log is full of trace-format support, timestamp precision, capture-length fixes, anonymization, payload hashing, DAG/NLANR support, and reports from networking researchers such as Vern Paxson, Mark Allman, Nicholas Weaver, and others.

Homebrew keeps ipsumdump installable as a packaged command, but formula analytics show very small usage. That fits the tool's niche: it is most valuable when someone has packet traces to reduce into stable, text-friendly fields for research or offline analysis.

### How it is used

The manual describes ipsumdump as a way to summarize IP packets into line-based ASCII output, with options for source and destination addresses, ports, timestamps, lengths, protocols, fragments, TCP flags, payload fields, anonymization, filtering, sampling, sorting, and optional tcpdump output.

Its design is particularly useful when packet data must survive shell pipelines, versioned experiments, or reproducible notebooks. Rather than keeping all analysis inside pcap readers, it lets users choose fields once and then process the result with ordinary text tools.

### Why package nerds care

ipsumdump is a package-nerd fossil in the good sense: a compact research utility that preserves a particular network-measurement workflow from the Click ecosystem. It is obscure, but it teaches why boring ASCII formats can be durable in packet-analysis pipelines.

### Timeline

- Version 1.3: Adds kernel-drop reporting for device captures.
- Version 1.25: Adds binary IPSummaryDump support.
- Version 1.55: Includes an initial ipaggcreate.
- Version 1.60: Documents a working ipaggcreate and updates internals around Click features.
- Version 1.86: Fixes UDP packet length reporting and updates Click.

### Related projects

- Click modular router is the architectural foundation used to read, filter, anonymize, and write packet streams.
- tcpdump/pcap, NetFlow summaries, DAG traces, and NLANR traces are important input formats.
- ipaggcreate and ipaggmanip are companion commands distributed with the package.

### Sources

- Homebrew formula metadata supplies package-manager availability and low-volume adoption context.
- The manual supplies command purpose, input formats, and field-level usage model.
- The project homepage supplies the overview, Click relationship, companion tools, and release-news timeline.


## Security Notes

narrow executable package without higher-risk signals.

- **Geiger risk:** green / low
- narrow executable package without higher-risk signals


## Combined YAML source

View the package source record on GitHub. [combined/ipsumdump.yml](https://github.com/mxcl/pkgdb/blob/main/combined/ipsumdump.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated package history
- pkgdb category and tag curation
- cross-ecosystem install command graph
