Hi i have a wire shark capture, in which there are specific information in each packet which i can see after decoding it as RTP. now i need those data into a csv file for further investigations. what is the procedure for getting those data in csv format.
asked 29 May '13, 02:34
If I understand the question correctly, one approach might be to add the field of interest as a displayed column, and then export the dissected packets.
One way you can add any field as a column, is by finding the field in the packet details pane, right click it, and then select "Apply as column". Another, harder, way to do it is to select Edit | Preferences | Columns and make changes to the displayed columns from there.
You can export all the displayed columns, for specific trace records or for all records, by selecting File | Export Packet Dissections | and then select the export format you prefer (.csv, .txt, etc)
answered 30 May '13, 21:51
One other way (especially if you need to do this on multiple files or multiple times) is to use tshark. You can use the following syntax:
You can change the header, separator etc, see tshark -h:
answered 31 May '13, 01:06