Wireshark mailing list archives
Re: Displaying column headers in Tshark output
From: Joerg Mayer <jmayer () loplof de>
Date: Fri, 24 Jan 2014 15:53:42 +0100
On Thu, Jan 23, 2014 at 05:38:09PM +0100, Matteo Arnò wrote:
I would like to convert a pcapng into text (from command line) for automated parsing using a SW tool. Is there any way to display the column headers for EACH packet, when converting the pcap to txt file using Tshark? i.e. I want this line: No. Time Source Destination Protocol Length Info above the information related to each packet. I tried -T fields with -e options, but apparently the header is only displayed in the first line of the txt file. I need it to be displayed with each packet (as it happens with the manual "export packet dissections" from wireshark).
tshark -r rtsp.pcap -Tfields -Eheader=y -e <field1> -e <field2> ... | perl -ne 'if ($header) { print "$header$_"; } else { $header=$_; }' Ciao Jörg -- Joerg Mayer <jmayer () loplof de> We are stuck with technology when what we really want is just stuff that works. Some say that should read Microsoft instead of technology. ___________________________________________________________________________ Sent via: Wireshark-users mailing list <wireshark-users () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-users Unsubscribe: https://wireshark.org/mailman/options/wireshark-users mailto:wireshark-users-request () wireshark org?subject=unsubscribe
Current thread:
- Displaying column headers in Tshark output Matteo Arnò (Jan 23)
- Re: Displaying column headers in Tshark output Joerg Mayer (Jan 24)