This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I would like to get logs out of pcap files (the pcap file is converted to windows .txt file using tshark command tshark -V -r {file}) so that i can display these packet capture logs in Splunk. What is the most common,standard, correct way of getting logs out from the pcap files that are converted to windows 7 .txt file especially when i am going to show the logs in the Splunk??

asked 18 Apr '12, 01:42

misteryuku's gravatar image

misteryuku
20242630
accept rate: 0%

edited 18 Apr '12, 01:44

1

You've now asked 14 questions and have not accepted any of the answers to any of them. You do realise that folks are attempting to help you out on their own time here? Please recognise any answers that have helped by clicking the check mark icon on the answer to "accept" them.

(18 Apr '12, 02:03) grahamb ♦

Yes sir, i understand. im very sorry about it.

(19 Apr '12, 23:21) misteryuku

No problem, but it motivates folks to answer your questions, and helps others who may have the same question to see an "accepted" answer.

(20 Apr '12, 01:56) grahamb ♦

As per the answers by Guy Harris to your very similar question here, this is really a question for the Splunk folks, not Wireshark.

permanent link

answered 18 Apr '12, 01:59

grahamb's gravatar image

grahamb ♦
19.8k330206
accept rate: 22%

The standard way to get log files is, as you already said in your question, to use TShark in the fashion you describe:

tshark -V -r {file} >log.txt

as a Windows command.

permanent link

answered 18 Apr '12, 11:11

Guy%20Harris's gravatar image

Guy Harris ♦♦
17.4k335196
accept rate: 19%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×238
×28
×2

question asked: 18 Apr '12, 01:42

question was seen: 7,370 times

last updated: 20 Apr '12, 01:56

p​o​w​e​r​e​d by O​S​Q​A