官术网_书友最值得收藏!

Capturing traffic with Tshark

Tshark can be used to capture network packets and/or display data from the capture or a previously saved packet trace file; packets can be displayed on the screen or saved to a new trace file.

The same syntax used to perform a basic capture using Dumpcap will work with Tshark as well, so we won't repeat that here. However, Tshark offers a very wide range of additional features, with a corresponding large number of command-line options that can, as in all Wireshark utilities, be viewed by typing tshark –h in the command prompt.

A number of Tshark options are to view statistics; an example of the command syntax and statistical results from a capture (after pressing Ctrl + C to end the capture) is illustrated in the following screenshot:

You will find an extensive number of details and examples on using statistics and other Tshark options at https://www.wireshark.org/docs/man-pages/tshark.html.

主站蜘蛛池模板: 临清市| 漾濞| 伊吾县| 大宁县| 金平| 襄樊市| 四会市| 凯里市| 璧山县| 仪征市| 舒兰市| 西丰县| 青阳县| 仪征市| 吉林省| 酒泉市| 浑源县| 明水县| 台北县| 双江| 乃东县| 宜兰市| 陇西县| 望奎县| 金川县| 海晏县| 梅州市| 双流县| 仪陇县| 南涧| 克拉玛依市| 永清县| 建阳市| 天峻县| 大英县| 柘城县| 道真| 大埔区| 大同市| 怀安县| 桂东县|