make wireshark.exe return json via cmd

asked 2021-01-04

learningnew

Hi, is there a way to use wireshark.exe that will return a json without using tshark? I mean to give it a pcap and get a json back but only with wireshark.exe without using the GUI, only cmd command. Thanks

answered 2021-01-04

grahamb

No. The entire purpose of tshark is to return dissection products in some textual form so why not use it?

Because tshark crashes with a specific dll dissector when wireshark gui does not

learningnew ( 2021-01-04 )

tshark shouldn't crash. Please raise an issue at the Wireshark GitLab issue tracker attaching the capture file if at all possible.

grahamb ( 2021-01-04 )

I'd rather know what that 'specific dll dissector' is. Not really interested in hunting down issues in closed source additions.

Jaap ( 2021-01-04 )

Could be in one of the distributed plugins.

grahamb ( 2021-01-04 )

Asked: 2021-01-04 09:17:11 +0000

Seen: 163 times

Last updated: Jan 04 '21