This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi,

To get some traffic statistics on multiple capture files in a folder, I am using a batch file running a simple tshark command e.g. "tshark -z io,stat,1,ip.addr==1.2.3.4" on each file one after the other, resulting in a large csv file containing the results.

Unluckily, the statistics generated by this command use Relative Time i.e. timestamps start at zero for each new file.

I was wondering why the output time format using tshark –z io,stat cannot be changed from relative to absolute, eg. using “–t ad”. I found on the mailing list a patch for tap-iostat.c which seem to allow such behaviour. http://www.wireshark.org/lists/wireshark-dev/200608/msg00213.html

So maybe this question is for devs/advisors, could it be integrated into an upcoming release? Thanks!

asked 16 Apr '12, 09:50

yul_analyzer's gravatar image

yul_analyzer
6558
accept rate: 0%


I opened bug 7207 to ensure that patch doesn't get lost again. You might want to subscribe yourself to that bug to track its progress.

permanent link

answered 27 Apr '12, 07:27

JeffMorriss's gravatar image

JeffMorriss ♦
6.2k572
accept rate: 27%

Patch has been applied on trunk and 1.8.0 is now including the corresponding revision, thx!

(05 Jul '12, 12:53) yul_analyzer
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×832
×86
×75

question asked: 16 Apr '12, 09:50

question was seen: 3,837 times

last updated: 05 Jul '12, 12:53

p​o​w​e​r​e​d by O​S​Q​A