Hi. I have a Wireshark capture of syslog data and I need to extract the raw data portion of the packet in ASCII. I can extract the data in the exact format I need by selecting a single packet and clicking 'Export Packet Bytes' from the File menu. But I need to extract this data for every packet in the trace, which isn't feasible in a trace containing thousands of packets. I've tried various permutations of the tshark command but I just can't seem to get it right. The closest I've come is this command, but the output is in hex:
tshark -r syslog.pcap --disable-protocol syslog -T fields -e data.data
What's the trick in getting this output in ASCII?
asked 10 Mar '17, 07:12
You could try:
answered 10 Mar '17, 07:18