Ask Your Question

Revision history [back]

Single line JSON output for tshark

For those of us who do (or would like to do) processing on ongoing streams of traffic from tshark it would be AMAZING if tshark had an option which would output a json dictionary of fields and values, 1 packet per line. Similar to the EK format, however with regular tshark field names. Maybe call it json_line or something. You would make SO many people very very happy :)