This is our old Q&A Site. Please post any new questions and answers at

Hi, I have done some command-line capturing of WLAN packets with dumpcap. Would like to use a display filter in tshark to extract some info in a table. Have found out how to get the MAC addresses for example, but I'm looking for a full list of header fields to be able to get other things out as well.

The only thing I have come across this far is this documentation of display filter (for Wireshark, not tshark):

Though, these filters don't work well whey I try them out in tshark. And what I get to work is not listed on these pages.

So I suspect that the filters in tshark look different than in Wireshark. Is this correct? And is there a complete list of tshark WLAN filters to find somewhere?



asked 05 Mar '15, 20:43

SamA's gravatar image

accept rate: 0%

edited 05 Mar '15, 20:58

the fields are the same. What exactly is not working with tshark and what is your tshark version (-v)?

(06 Mar '15, 02:19) Kurt Knochner ♦

To get a complete list of fields (for all protocols, so it's very big), use:

tshark -G fields > fields.txt

permanent link

answered 06 Mar '15, 02:22

grahamb's gravatar image

grahamb ♦
accept rate: 22%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 05 Mar '15, 20:43

question was seen: 2,491 times

last updated: 06 Mar '15, 02:22

p​o​w​e​r​e​d by O​S​Q​A