This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Right now I am using: tshark -r "C:\Users\admin\Desktop\capture.cap" -qz "conv,ip"

This displays host IP conversations with hosts that have the most frames topping the results. Seems typically the hosts with the most frames usually have the most bytes in their conversations, but not always. Is there anyway to make the hosts with the most bytes in these conversations appear at the top, then descending in value by byte count?

asked 23 Feb '16, 10:24

zer0day's gravatar image

zer0day
217811
accept rate: 60%


Looking at the source, no, the sorting is hard-coded to be by the number of frames.

You could raise an enhancement request to request the functionality.

permanent link

answered 25 Feb '16, 15:27

JeffMorriss's gravatar image

JeffMorriss ♦
6.2k572
accept rate: 27%

Thanks for taking the time to look, much appreciated.

(27 Feb '16, 17:47) zer0day

Try this:

for aa in `ls *.pcap`; do
    echo -------------
    echo ==== $aa ====
    echo "                                               |       <-      | |       ->      | |     Total     |    Relative    |   Duration   |"
    echo "                                               | Frames  Bytes | | Frames  Bytes | | Frames  Bytes |      Start     |              |"
    tshark -r $aa -q -z conv,ip | grep -v -E "====|Conversations|Filter|Total|Frames" | sort -nr -k 9 | head
done

or just

tshark -r file.pcap -q -z conv,ip | grep -v -E "====|Conversations|Filter|Total|Frames" | sort -nr -k 9 | head
permanent link

answered 14 Jul, 15:09

gag99's gravatar image

gag99
61
accept rate: 0%

edited 15 Jul, 05:30

JeffMorriss's gravatar image

JeffMorriss ♦
6.2k572

The above script appears to be bash based along with several common *nix utilities and as such, won't work for the OP who appears to be running Windows.

The OP could install a *nix compatibility tool such as Cygwin or mingw (as provided by Git for Windows) to run the scripts or convert them to something that works out of the box, e.g. PowerShell.

(15 Jul, 07:20) grahamb ♦
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×832
×178
×86
×32
×10

question asked: 23 Feb '16, 10:24

question was seen: 1,336 times

last updated: 15 Jul, 07:20

p​o​w​e​r​e​d by O​S​Q​A