This is our old Q&A Site. Please post any new questions and answers at
  1. For my project I want Wireshark to directly start saving packets as I start it. I need packets in plain text file format ( 2. is there automatic exporting possible by doing any setting in wireshark ? ) How above two can be done .....

asked 16 Feb '14, 01:27

WIDS's gravatar image

accept rate: 0%

You can't do that with Wireshark. That's what tshark is made for.

tshark -Vxnr input.pcap


tshark -nr input.pcap -T pdml

or even

tshark -nr input.pcap -T fields -e frame.number -e -e radiotap.radiotap.db_antsignal -e -e wlan.da -e ip.src -e ip.dst -E separator=; -E header=y

List of fields:

Then parse the output of tshark with whatever language you prefer (in your case probably Java).

HINT: If you run tshark/Wireshark continuously, you will eventually get into trouble, as both tools are not designed as long term, real time monitoring tools. For both the memory usage will increase steadily, as both store state information about several things (sessions, etc.), and never release that memory, until the process ends.

See also some lengthy discussion on this site, regarding tshark as a long term, real time monitoring solution and the problems that can arise.


permanent link

answered 16 Feb '14, 02:26

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
accept rate: 15%

edited 16 Feb '14, 03:12

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 16 Feb '14, 01:27

question was seen: 3,175 times

last updated: 16 Feb '14, 03:12

p​o​w​e​r​e​d by O​S​Q​A