This is our old Q&A Site. Please post any new questions and answers at

Hu, guys!

Is it possible to add mac-addresses into default output format for tshark?

asked 23 Oct '13, 02:15

itonohito's gravatar image

accept rate: 0%

The default columns that Wireshark uses are specified by the following in tshark:

  • Windows:

    tshark -o "column.format:\"No.\",\"%Cus:frame.number:0:R\",\"Time\",\"%t\",\"Source\",\"%s\",\"Destination\",\"%d\",\"Protocol\",\"%p\",\"Length\",\"%L\",\"Info\",\"%i\""

  • *Nix:

    tshark -o 'column.format:"No.","%Cus:frame.number:0:R","Time","%t","Source","%s","Destination","%d","Protocol","%p","Length","%L","Info","%i"'

If you want to display the mac addresses, you can modify that to use one or more of the following, giving any name you want for the format:

Format  Description
%hd     Hardware dest addr
%hs     Hardware src addr
%rhd    Hw dest addr (resolved)
%uhd    Hw dest addr (unresolved)
%rhs    Hw src addr (resolved)
%uhs    Hw src addr (unresolved)

For example:

`tshark -o 'column.format:"No.","%Cus:frame.number:0:R","Time","%t","HwSrc","%hs","HwDst","%hd"'`

If you're using a version of Wireshark post r52627, then you can run tshark -G column-formats to see all the available column options. If not, then you can refer to the Wireshark source code for them.

permanent link

answered 24 Oct '13, 10:20

cmaynard's gravatar image

cmaynard ♦♦
accept rate: 20%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 23 Oct '13, 02:15

question was seen: 1,863 times

last updated: 24 Oct '13, 10:20

p​o​w​e​r​e​d by O​S​Q​A