This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I would like to export the decrypted data from certain packets in my pcap file to a text file (preferably csv file).

I know that right now tshark does not support decryption. How do I use wireshark to save decrypted data. I tried "export PDU">"dlt USer" option but the new file that gets loaded in wireshark is empty. Not quite sure what is going on.

Is there any other option?

asked 17 Jan '16, 13:35

hvs's gravatar image

hvs
6446
accept rate: 0%


Read carefully (till the very last comment) the answer thread of this older question. You won't get csv but you will get the decrypted data in xml.

permanent link

answered 17 Jan '16, 13:48

sindy's gravatar image

sindy
6.0k4851
accept rate: 24%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×165
×62

question asked: 17 Jan '16, 13:35

question was seen: 3,885 times

last updated: 17 Jan '16, 13:48

p​o​w​e​r​e​d by O​S​Q​A