This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Summmary line in pcap

0

Does the summary line in pcap follow a specific format. I have a dump from wireshark based on only the summary line and i need to add tcp/ip analysis based on ftp/http/icmp etc. Any suggestions

This question is marked "community wiki".

asked 07 Aug '14, 08:50

anilkumarxceed's gravatar image

anilkumarxceed
1111
accept rate: 0%


One Answer:

0

The content of the summary line in Wireshark is specified by the highest level dissector, e.g. if you have a TCP packet with no payload the TCP dissector decides what to put in. For HTTP packets, its the HTTP dissector, etc.

If you need to add more details you should just configure all columns to show what you need, and then use the "Export packet dissections" to CSV feature to save the list.

answered 07 Aug '14, 08:53

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%