This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I am using wireshark 1.6.11 on Fedora 17. I can see summary of packets grouped by their size from statistics --> packet lengths --> create state (without any filter)

Is there a way to get this on command line or any script that you might be aware of ?

I tried using various options with -z but no luck till now.

Thanks in advance.

asked 28 Nov '12, 01:23

nehaldattani's gravatar image

nehaldattani
6114
accept rate: 0%

edited 28 Nov '12, 01:23


with built-in commands:

tshark -nr input.pcap -T fields -e frame.len | sort -n | uniq -c

if your distribution supports gsl-histogram:

tshark -nr input.pcap -T fields -e frame.len | gsl-histogram 0 1500 30

Please check the man page of gsl-histogram for the options.

To install gsl-histogram, I had to run this command on Ubuntu: apt-get install gsl-bin.

If that's not exactly what you need, you could write a short script (perl/python).

Regards
Kurt

permanent link

answered 28 Nov '12, 03:27

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.7k1037236
accept rate: 15%

edited 28 Nov '12, 03:28

I got what I wanted. I think using sum with awk will give me the values in % . but thank you for pointing me in right direction.

(28 Nov '12, 03:49) nehaldattani
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×832
×86
×41

question asked: 28 Nov '12, 01:23

question was seen: 8,289 times

last updated: 28 Nov '12, 03:50

p​o​w​e​r​e​d by O​S​Q​A