Ask Your Question

Single line JSON output for tshark

asked 2020-08-03 19:21:43 +0000

For those of us who do (or would like to do) processing on ongoing streams of traffic from tshark it would be AMAZING if tshark had an option which would output a json dictionary of fields and values, 1 packet per line. Similar to the EK format, however with regular tshark field names. Maybe call it json_line or something. You would make SO many people very very happy :)

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted

answered 2020-08-03 19:34:28 +0000

Guy Harris gravatar image

That's not a question. :-)

Requests for new features are best made on the Wireshark Bugzilla, where they can be more easily 1) found (by querying for enhancements) and 2) tracked through the development process (commits can have "Bug: {bug number}" lines in the commit message to tie them to the bug/enhancement request, and the request can be closed once the feature is implemented).

edit flag offensive delete link more


Excellent, thank you! I will move my request there :)

bmoresecure gravatar imagebmoresecure ( 2020-08-03 19:54:17 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2020-08-03 19:21:43 +0000

Seen: 139 times

Last updated: Aug 03