This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I would like to know how long the TCP connection lasted using tshark, in wiresahrk this info is represented in the conversation statistics

asked 18 Oct '11, 17:20

ddayan's gravatar image

ddayan
41151720
accept rate: 0%


If you know the TCP stream index for the connection, you can pull out the frame.time_epoch field for the first and last frames and subtract them.

tshark -r <filename> -R "tcp.stream eq <index>" -T fields -e frame.time_epoch

That will print out the arrival times for each packet in the stream. You can subtract the first number from the last to get the total duration as Wireshark would calculate it.

permanent link

answered 24 Oct '11, 18:15

zachad's gravatar image

zachad
331149
accept rate: 21%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×832
×752

question asked: 18 Oct '11, 17:20

question was seen: 6,620 times

last updated: 24 Oct '11, 18:15

p​o​w​e​r​e​d by O​S​Q​A