This is our old Q&A Site. Please post any new questions and answers at

I'm trying to resolve ip addresses using a hosts file and it works well with the wireshark GUI (1.8.7) when the hosts file is in my Personal Configuration folder. Now I came across the tshark -H <hosts file> which seemed quite interesting

  -H <hosts file>       read a list of entries from a hosts file, which will
            then be written to a capture file. (Implies -W n)

So I tried the following command that will save host name resolution records along with captured packets. as per

tshark -r swg186.pcapng -H hosts -w swg186.dns.pcapng -F pcapng -W n

Well, obviously it didn't :-( - or I'm not seeing it...

Am i missing something here?

Yes, resolution works on other machine without external host file. alt text

asked 24 Oct '13, 05:29

mrEEde's gravatar image

accept rate: 20%

edited 24 Oct '13, 06:45

Looks like it actually did what it was supposed to do... Every address is now resolved - even without a matching hosts file in the wireshark GUI.
Will send it to another machine and check

(24 Oct '13, 06:08) mrEEde

Answering my own - stupid? - question ... The name resolution is done without any external resources (hosts file or DNS) once the command

tshark -r swg186.pcapng -H hosts -w swg186.dns.pcapng -F pcapng -W n

is issued. This information is stored (somewhere) in the pcapng file.

permanent link

answered 24 Oct '13, 06:49

mrEEde's gravatar image

accept rate: 20%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 24 Oct '13, 05:29

question was seen: 2,943 times

last updated: 24 Oct '13, 06:49

p​o​w​e​r​e​d by O​S​Q​A