ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: Re: [Wireshark-users] programmatically controlled Wireshark

From: Jaap Keuter <jaap.keuter@xxxxxxxxx>
Date: Wed, 25 Nov 2009 12:25:59 +0100
Hi,

You can do all this from the commandline. There's no other control interface.

Thanks,
Jaap

Send from my iPhone

On 25 nov 2009, at 10:54, Ola Liljedahl <ola.liljedahl@xxxxxxxx> wrote:

We have tools for analyzing and displaying logs and these logs may refer
to captured
packets (the log may actually contain the packets but we do not intend
to write 10000
dissectors for our log analyzer when Wireshark already does this). We
indent to save
those captured packets to a file in the pcap format and then launch
Wireshark for
analyzing and viewing the packets.

I wonder if there is any programmatic interface for controlling
Wireshark so that it
can load different capture files and jump to specific packets (perhaps
identified by
time stamp) in the capture as commanded by another program. Maybe
Wireshark could listen
to a TCP port to which you can connect and send commands. Or maybe some
more standardized
IPC mechanism.

I scanned through the User's Guide but could not find anything similar
to what we want
to do.

Thanks,

Ola Liljedahl


___________________________________________________________________________


Sent via: Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx >
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe