This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Does the summary line in pcap follow a specific format. I have a dump from wireshark based on only the summary line and i need to add tcp/ip analysis based on ftp/http/icmp etc. Any suggestions

This question is marked "community wiki".

asked 07 Aug '14, 08:50

anilkumarxceed's gravatar image

anilkumarxceed
1111
accept rate: 0%


The content of the summary line in Wireshark is specified by the highest level dissector, e.g. if you have a TCP packet with no payload the TCP dissector decides what to put in. For HTTP packets, its the HTTP dissector, etc.

If you need to add more details you should just configure all columns to show what you need, and then use the "Export packet dissections" to CSV feature to save the list.

permanent link

answered 07 Aug '14, 08:53

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×238
×16
×11

question asked: 07 Aug '14, 08:50

question was seen: 1,084 times

last updated: 07 Aug '14, 08:53

p​o​w​e​r​e​d by O​S​Q​A