How to get printable text of multiple packets at once?

asked 2018-04-10 08:56:25 +0000

We are getting all the SQL queries from the packets being captured by wireshark. There are times when the packets are in hundreds and it is very laborious to get the printable text of the packet one by one manually. There is also a risk of missing out some packets if we click the wrong line number.

Is there a way to get them by batch or by selecting several packets?

Thanks, GJ

2 Answers

answered 2018-04-10 09:54:54 +0000

What is the field that you are printing out? Select the field in the packet details tree and look at the status bar, the field name is in parentheses.

With the field name you can use tshark (the command line version of Wireshark) to print out only that field using the-T fields -e your fieldname options.

answered 2018-04-10 10:00:53 +0000

If you are looking for text output you should look into using tshark, combined with the proper display filter and output format (eg. json, tabs or text) and post process from there.

Asked: 2018-04-10 08:56:25 +0000

Seen: 2,338 times

Last updated: Apr 10 '18