This is our old Q&A Site. Please post any new questions and answers at


I'm Automatically capturing logs in .pcap format using below command dumpcap.exe -i 4 -a files:3 -a filesize:5 -w test.pcap

how can convert this files to .txt format automatically using dumpcap command....

asked 02 Mar '13, 20:55

Irsh's gravatar image

accept rate: 0%

dumpcap always writes pcapng or pcap files by default, depending on the version of the executable, so the "logs" are always in a binary format. No way around that. If you need text files you can try to use tshark to display decoded data after it has been written to disk, or you could use Wireshark to export the packets to decoded .txt format manually.

Why do you need .txt format anyway? Usually it is more useful to have the binary format since it can be worked with much easier.

permanent link

answered 03 Mar '13, 05:02

Jasper's gravatar image

Jasper ♦♦
accept rate: 18%

edited 03 Mar '13, 05:03

Hi, I'm Running a program where certain data comes in hidden format where wireshark Picks. What I want is to get that data to another Program .... can I use tshark to achieve this ? If so... what is the command please. Thanks

(03 Mar '13, 08:17) Irsh

what do you mean by "hidden format"? Sounds like Wireshark/Tshark just do not have dissectors for it - if so, you'll be stuck with undecoded bytes either way.

So do I get this correctly - you want to extract payload bytes that Wireshark/TShark does not decode?

(03 Mar '13, 17:23) Jasper ♦♦
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 02 Mar '13, 20:55

question was seen: 2,876 times

last updated: 03 Mar '13, 17:23

p​o​w​e​r​e​d by O​S​Q​A