Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] tcp.time_delta column with tshark

From: vincent paul <amoteluro@xxxxxxxxx>
Date: Sat, 29 Jan 2011 00:26:40 -0800 (PST)
Hi All,

1) I try to use tshark to export a capture into csv file.  I use -T fields -E separator=, -e tcp.time_delta.......  I could see other column data but not tcp.time_delta .  Any idea.

2)What is the filter to use with tshark statistic to print out the duration of every TCP connections in a capture (as "duration" column in Statistics--->Conversation table).

3) With "-T text" option, tshark will print out packets' summary line by line displayed by wireshark's GUI.  Is there any way to select some column data not all columns, or additional column data (i.e. probably "-o option" but how to set up related filter/file...)

4) What is needed and how to see packets' content exchange between client and its proxy (not web server).

Any idea, help,educational document is greatly appreciated.

Best Regards,
PV