This is our old Q&A Site. Please post any new questions and answers at


As far as I know it is possible to mark packets but as the user guide states the changes will not persist after you close wireshark. I would like to know if anyone has figured out a way to bypass that so that.

Moreover I would like to know if it possible to mark specific packets groups in specific ways/tags/colours. For example, packets

Ideally, at some point I would also like to include this flag at tshark command line and export the marks along with other packet headers into a text file.

Do you think that it might be possible somehow? Any pointers?

Much appreciated.

asked 06 Nov '14, 15:45

BadAcidTrip's gravatar image

accept rate: 0%

No that's not possible and the file format pcap-ng does not have an option to do that I think. But adding a packet comment might give you part of what you want q's that can be saved in an pcap-ng file.

permanent link

answered 06 Nov '14, 21:18

Anders's gravatar image

Anders ♦
accept rate: 17%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 06 Nov '14, 15:45

question was seen: 2,160 times

last updated: 06 Nov '14, 21:18

p​o​w​e​r​e​d by O​S​Q​A