Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] Is there a tshark option to save just RTP Header?

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Thu, 31 May 2007 17:19:41 -0700


On May 31, 2007, at 5:13 PM, Stephen Fisher wrote:

On Thu, May 03, 2007 at 05:29:24PM -0400, Kerry L Foster wrote:

Is it possible to control what information is being saved by tshark
into the output capture file?

The only way that I know of is the -s <snapshot len> option, which
specifies how many bytes of each packet to read/save.  This could be
used in your case as long as all of the packets had the exact same
length for the lower level protocols (ethernet, ip, udp, etc.)

Unfortunately, that can be used to *throw away* the RTP header, but can't be used to save *only* the RTP header - a snapshot length of N means "save only the first N bytes of the packet".

  • References:
    • Re: [Wireshark-users] Is there a tshark option to save just RTP Header?
      • From: Stephen Fisher
  • Prev by Date: Re: [Wireshark-users] Stop process in Wireshark 0.99.5
  • Next by Date: Re: [Wireshark-users] Is there a tshark option to save just RTP Header?
  • Previous by thread: Re: [Wireshark-users] Is there a tshark option to save just RTP Header?
  • Next by thread: Re: [Wireshark-users] Is there a tshark option to save just RTP Header?
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation