1
0
Fork 0
mirror of https://github.com/tldr-pages/tldr.git synced 2025-07-01 22:35:23 +02:00
tldr/pages/linux/tshark.md
Managor 79b8d3e3b8
*: replace … with individual dots and refresh pages (#16368)
Co-authored-by: Darío Hereñú <magallania@gmail.com>
Co-authored-by: Sebastiaan Speck <12570668+sebastiaanspeck@users.noreply.github.com>
2025-05-04 10:20:26 +03:00

769 B

tshark

Packet analysis tool, CLI version of Wireshark. More information: https://tshark.dev/.

  • Monitor everything on localhost:

tshark

  • Only capture packets matching a specific capture filter:

tshark -f '{{udp port 53}}'

  • Only show packets matching a specific output filter:

tshark -Y '{{http.request.method == "GET"}}'

  • Decode a TCP port using a specific protocol (e.g. HTTP):

tshark -d tcp.port=={{8888}},{{http}}

  • Specify the format of captured output:

tshark -T {{json|text|ps|...}}

  • Select specific fields to output:

tshark -T {{fields|ek|json|pdml}} -e {{http.request.method}} -e {{ip.src}}

  • Write captured packet to a file:

tshark -w {{path/to/file}}

  • Analyze packets from a file:

tshark -r {{path/to/file.pcap}}