Terry, that again depends on what Voip protocol you are analyzing.
 
For instance in SIP, media information is exchanged commonly over SDP (Session Description Protocol), which carries the port information over which the media is to be exchanged.
you can use sdp.media.port switch in conjunction with -V to see what all ports are being used for Media Transfer.
 
something like
 
tshark -r <pcap you want to read> sdp.media.port -V | grep -w "Media Port" (I dont know a better way to get the media ports)
 
You can use a small script to store these ports and supply the same to tshark to automate the process.
 
--
Sandeep Nitta
 
 
On Fri, Aug 29, 2008 at 12:17 AM, Terry Martin 
<tmartin@xxxxxxxxxxxxxxxx> wrote:
Thanks that is a good start
 
This gives me the signaling information, which I want.  I also want the information over the media which is usually on another port?  Is there a way to indentify that and collect that?
 
That is why I was trying to find a way to automate what is done in wireshark, where it will analyse a VoIP call.  I want to see if I can do that in Tshark.  Is that possible?
 
Terry Martin
TimeData Corporation
VP of Network Operation
work:     212-644-1600 X3
Cell:      503-318-8909
 
 
 
 
You need to identify which Voip protocols are being used in your Voip Traffic.
 
Ex: SIP commonly uses port 5060 for UDP and 5061 for TCP
 
Similarily, once you identify which protocol is being used in your network and on which port it traverses, you are ready to go ahead
 
Say, all your traffic goes on port 5060 and on "x" interface, 
 
you can use the following filter
 
tshark -i x port 5060 -w <name of pcap that you want to analyze"
 
you can look at the man page of tshark and what functionality the -z switch provides to further analyze the captued trace file.
 
On Thu, Aug 28, 2008 at 9:15 PM, Terry Martin <tmartin@xxxxxxxxxxxxxxxx> wrote:
I am new to the list but I am trying to understand how to collect VoIP traffic using Tshark and generate similar reports to what you can get when you use the VoIP analysis in wireshark?  Can any one point me the right direction to obtain that type of data?  How to setup the filters
 
Thanks
 
Terry Martin
TimeData Corporation
VP of Network Operation
work:     212-644-1600 X3
Cell:      503-318-8909
 
  
_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
https://wireshark.org/mailman/listinfo/wireshark-users
 
 
     
_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
https://wireshark.org/mailman/listinfo/wireshark-users