This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Get offsets for each fields with tshark

0

Tshark command like

tshark -r <pcapFile> -V -P

can produce detailed info about fields of a packet and the output can be piped to other application for some processing. Wonder if it's possible to get information on offsets of each fields in addition. This is an analogy to wireshark where you click a decoded field, the relevant bytes in the pcap got highlighted.

Thanks.

asked 26 Mar '15, 20:34

sharkfun's gravatar image

sharkfun
26559
accept rate: 0%


One Answer:

0

That's not possible with the current release. It would require a code change. If you want/need that feature, please file an enhancement bug at https://bugs.wireshark.org

Regards
Kurt

answered 30 Mar '15, 04:22

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

Thanks Kurt, I created a ticket on this.

(30 Mar '15, 06:43) sharkfun

Please post the bug ID or the link here for other users.

(30 Mar '15, 06:52) Kurt Knochner ♦

Sorry didn't see this comment earlier. The bug ID is 11097. Thanks.

(07 May '15, 11:57) pktUser1001