Wireshark-dev: Re: [Wireshark-dev] Need to export IP Packet length to a CSV file from a capture

Date: Tue, 30 Oct 2007 08:28:42 -0700 (PDT)
Thank you very much for your help Sake. It worked.

Is there anyway I can have this done through the GUI

The user preference options in the Wireshark GUI
allows one to add remove specific fields by adding
removing column. However it doesn't allow you to add
delete protocol specific fields like IP.packet length.
It would be excellent to have this done through the

--- Sake Blok <sake@xxxxxxxxxx> wrote:

> > I needed some help on exporting data captured in
> .cap
> > to a CSV file.
> > My main intention to capture the following feilds.
> > Source Address, Destination Address, Source POrt
> > Destination Port and IP Packet Length.
> > 
> > I am able to export all but the last field i.e. IP
> > Packet length. I don't want the packet bytes but
> > specifically want the IP Total Length field.
> How about:
> tshark -i 7 -T fields -e ip.src -e tcp.srcport -e
> ip.dst -e tcp.dstport -e ip.len
> Hope this helps, Cheers,
> Sake
> _______________________________________________
> Wireshark-dev mailing list
> Wireshark-dev@xxxxxxxxxxxxx

Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 