tshark -T ek or JSON

asked 2021-04-11

ccncore

I am trying to run tshark -T ek or -T json but the only options available are tshark: Invalid -T parameter. It must be "ps", "text", "pdml", "psml" or "fields". I am sure iI am doing something wrong - any ideas appreciated.

Add output of tshark -v which includes version and platform information.

Chuckc ( 2021-04-11 )


# tshark -v 
TShark 1.10.14 (Git Rev Unknown from unknown)
ccncore ( 2021-04-12 )

answered 2021-04-12

Chuckc

updated 2021-04-12 18:41:40 +0000

You will need to upgrade to a newer version of tshark:
Wireshark 2.2.0 Release Notes

The Qt UI, GTK+ UI, and TShark can now export packets as JSON. 
TShark can additionally export packets as Elasticsearch-compatible JSON.
Thanks Chuck much appreciated the only other thing I am stuck on is how to get that version into Centos 7

ccncore ( 2021-04-12 )

It's not terrible to build from the source.
Definitely make sure to run tools/ to get all the dependencies.
Link to source

Chuckc ( 2021-04-12 )

