I need to filter out either option A or option A below of a pcap file:
A. The connection speed of a transmission (aka mbps), the number of bits for that packet transmission, and the starting time of the transmission; may need to be of a specific protocol
Here is the code I currently have, which exports only the packet start time of ip transmissions:
The problem I am having is that I am not finding anything that allows me to export the specific information listed in either A. or B. Any help would be appreciated.
PS: I do know that "ip.len" can be used to find instances of specific lengths, but I want to find the lengths of specific instances (aka certain protocols or simply a transmission occurrence).
Need a response as soon as possible, if possible.
asked 16 Dec '15, 12:49
edited 16 Dec '15, 13:01
If I get you right, you need to calculate an average transmission speed, calculated as (sum of lengths of all packets meeting the display filter) / (timestamp of the last packet - timestamp of the first packet). One way, which allows you to use your favourite scripting language, would be to let tshark display tuples (
answered 16 Dec '15, 13:31
edited 16 Dec '15, 13:37