Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

Tshark doesnt detect RTP "rtp.heuristic_rtp: TRUE"

Hi, I want Tshark to output RTP statistics to a textfile, but it only works in one direction. Reason is that in wireshark you need to "decode as" the packets as "STUN" packets. Then it is correctly detected and handled as RTP traffic (picture). I specified the Wireshark profile, but tshark still only show RTP statistics for one direction.

tshark.exe -r .\Teams.pcapng -C "UDP VOIP (STUN)" -o "rtp.heuristic_rtp: TRUE" -qz rtp,streams >text.txt

Questions: 1) Anyone knows how to make it work with tshark? Or... 2) Can you remove STUN headers with tshark/editcap so that it is detected as RTP traffic?

Thank you

Tshark doesnt detect RTP "rtp.heuristic_rtp: TRUE"

Hi, I want Tshark to output RTP statistics to a textfile, but it only works in one direction. Reason is that in wireshark you need to "decode as" the packets as "STUN" packets. Then it is correctly detected and handled as RTP traffic (picture). I specified the Wireshark profile, but tshark still only show RTP statistics for one direction.

tshark.exe -r .\Teams.pcapng -C "UDP VOIP (STUN)" -o "rtp.heuristic_rtp: TRUE" -qz rtp,streams >text.txt

Questions: 1) Anyone knows how to make it work with tshark? Or... Or...

2) Can you remove STUN headers with tshark/editcap so that it is detected as RTP traffic?

Thank you

Tshark doesnt detect RTP "rtp.heuristic_rtp: TRUE"

Hi, I want Tshark to output RTP statistics to a textfile, but it only works in one direction. Reason is that in wireshark you need to "decode as" the packets as "STUN" packets. Then it is correctly detected and handled as RTP traffic (picture). I specified the Wireshark profile, but tshark still only show RTP statistics for one direction.

tshark.exe -r .\Teams.pcapng -C "UDP VOIP (STUN)" -o "rtp.heuristic_rtp: TRUE" -qz rtp,streams >text.txt

Questions: Questions:

1) Anyone knows how to make it work with tshark? Or...

2) Can you remove STUN headers with tshark/editcap so that it is detected as RTP traffic?

Thank you

Tshark doesnt detect RTP "rtp.heuristic_rtp: TRUE"

Hi, I want Tshark to output RTP statistics to a textfile, but it only works in one direction. Reason is that in wireshark you need to "decode as" the packets as "STUN" packets. packets, because RTP is encapsulated inside STUN. Then it is correctly detected and handled as RTP traffic (picture). I specified the Wireshark profile, but tshark still only show RTP statistics for one direction.

tshark.exe -r .\Teams.pcapng -C "UDP VOIP (STUN)" -o "rtp.heuristic_rtp: TRUE" -qz rtp,streams >text.txt

Questions:

1) Anyone knows how to make it work with tshark? Or...

2) Can you remove STUN headers with tshark/editcap so that it is detected as RTP traffic?

Thank you

Tshark doesnt detect RTP "rtp.heuristic_rtp: TRUE"

Hi, I want Tshark to output RTP statistics to a textfile, but it only works in one direction. Reason is that in wireshark you need to "decode as" the packets as "STUN" packets, because RTP is encapsulated inside STUN. Then it is correctly detected and handled as RTP traffic (picture). I specified the Wireshark working (decode as)Wireshark profile, but tshark still only show RTP statistics for one direction.

tshark.exe -r .\Teams.pcapng -C "UDP VOIP (STUN)" -o "rtp.heuristic_rtp: TRUE" -qz rtp,streams >text.txt

Questions:

1) Anyone knows how to make it work with tshark? Or...

2) Can you remove STUN headers with tshark/editcap so that it is detected as RTP traffic?

Thank you

Tshark doesnt detect RTP "rtp.heuristic_rtp: TRUE"

Hi, I want Tshark to output RTP statistics to a textfile, but it only works in one direction. Reason is that in wireshark you need to "decode as" the packets as "STUN" packets, because RTP is encapsulated inside STUN. Then it is correctly detected and handled as RTP traffic (picture). (picture) in wireshark, but not in tshark. :( I specified the working (decode as)Wireshark profile, but tshark still only show RTP statistics for one direction.

tshark.exe -r .\Teams.pcapng -C "UDP VOIP (STUN)" -o "rtp.heuristic_rtp: TRUE" -qz rtp,streams >text.txt

Questions:

1) Anyone knows how to make it work with tshark? Or...

2) Can you remove STUN headers with tshark/editcap so that it is detected as RTP traffic?

Thank you

Tshark doesnt detect RTP "rtp.heuristic_rtp: TRUE"

Hi, I want Tshark to output RTP statistics to a textfile, but it only works in one direction. Reason is that in wireshark you need to "decode as" the packets as "STUN" packets, because sending side RTP is encapsulated inside STUN. STUN (receiving side works fine). Then it is correctly detected and handled as RTP traffic (picture) in wireshark, but not in tshark. :( I specified the working (decode as)Wireshark profile, but tshark still only show RTP statistics for one direction.

tshark.exe -r .\Teams.pcapng -C "UDP VOIP (STUN)" -o "rtp.heuristic_rtp: TRUE" -qz rtp,streams >text.txt

Questions:

1) Anyone knows how to make it work with tshark? Or...

2) Can you remove STUN headers with tshark/editcap so that it is detected as RTP traffic?

Thank you

Tshark doesnt detect RTP "rtp.heuristic_rtp: TRUE"

Hi, I want Tshark to output RTP statistics to a textfile, but it only works in one direction. Reason is that in wireshark you need to "decode as" the packets as "STUN" packets, because sending side RTP is encapsulated inside STUN (receiving side works fine). Then it is correctly detected and handled as RTP traffic (picture) in wireshark, but not in tshark. :( I specified the working (decode as)Wireshark profile, but tshark still only show RTP statistics for one direction.

tshark.exe -r .\Teams.pcapng -C "UDP VOIP (STUN)" -o "rtp.heuristic_rtp: TRUE" -qz rtp,streams >text.txt

Questions:

1) Anyone knows how to make it work with tshark? Or...

2) Can you remove STUN headers with tshark/editcap so that it is detected as RTP traffic?

Thank you

Tshark doesnt detect RTP "rtp.heuristic_rtp: TRUE"

Hi, I want Tshark to output RTP statistics to a textfile, but it only works in one direction. Reason is that in wireshark you need to "decode as" the packets as "STUN" packets, because sending side RTP is encapsulated inside STUN (receiving side works fine). Then it is correctly detected and handled as RTP traffic (picture) in wireshark, but not in tshark. :( I specified the working (decode as)Wireshark profile, but tshark still only show RTP statistics for one direction.

tshark.exe -r .\Teams.pcapng -C "UDP VOIP (STUN)" -o "rtp.heuristic_rtp: TRUE" -qz rtp,streams >text.txt

Questions:

1) Anyone knows how to make it work with tshark? Or...

2) Can you remove STUN headers with tshark/editcap so that it is detected as RTP traffic?

Thank you