ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: Re: [Wireshark-users] format of output file

From: "Peter Valdemar Mørch (Lists)" <4ux6as402@xxxxxxxxxxxxxx>
Date: Thu, 09 Jul 2009 09:04:36 +0200
Guy Harris guy-at-alum.mit.edu |Lists| wrote:
How can keep the ringbuffer functionalty and have the files in text format?

By modifying TShark to support such a feature; it currently doesn't support that.

Would it work for you to use the ringbuffer and keep the files in pcap format, and then when you need them, convert the pcap files to text files with:

cat file.pcap | tshark -i -

or even (bash syntax):

for f in *.pcap ; do
   cat $f | tshark -i - > $f.txt
done

?

Peter

--
Peter Valdemar M�rch
http://www.morch.com