This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I routinely have large pcap files that I need to export the HTTP objects from. How can I do this via command line? Using the GUI is a very slow process with large files.

asked 28 Aug '14, 10:41

stom's gravatar image

stom
11113
accept rate: 0%

edited 28 Aug '14, 10:41

I'm actually looking to export the object themselves to a folder, not just have them placed into another PCAP that I'll then still have to open and manually export them from. Any way to do this? The proposed solution might make the files smaller and easier to deal with but still isn't the automation I was looking for.

(29 Aug '14, 07:54) stom

As of Wireshark 2.3.0, you can export HTTP objects with tshark. (Wireshark 2.3.0 hasn't been released yet, so you can grab a daily build from here.)

To extract HTTP objects from the command-line, run the following command:

tshark -r mypcap.pcap --export-objects "http,destdir"
permanent link

answered 15 Dec '16, 16:52

moshe's gravatar image

moshe
21125
accept rate: 0%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×37
×6

question asked: 28 Aug '14, 10:41

question was seen: 9,562 times

last updated: 15 Dec '16, 16:52

p​o​w​e​r​e​d by O​S​Q​A