This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi, How do I use the maxmind Geo IP databases when using tshark, using the terminal (or how do tell tshark to refer to the downloaded database files)? There is no gui on the system so I cannot add using wireshark.

Thanks, qwerfdsa

asked 04 Mar '13, 18:54

qwerfdsa's gravatar image

qwerfdsa
16225
accept rate: 0%


You will need to have a ~/.wireshark/geoip_db_paths file; it should contain a line giving the absolute path name of the GeoIP database directory, in double-quotes. For example, mine has the line

"/Users/gharris/GeoIP"

because they're stored in a directory named GeoIP under my home directory.

permanent link

answered 04 Mar '13, 21:54

Guy%20Harris's gravatar image

Guy Harris ♦♦
17.4k335196
accept rate: 19%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×832
×37
×18
×4

question asked: 04 Mar '13, 18:54

question was seen: 3,544 times

last updated: 26 Aug '13, 15:40

p​o​w​e​r​e​d by O​S​Q​A