![]() ![]() z : Get TShark to collect various types of statistics and display the result after finishing reading the capture file. ![]() q : When reading a capture file, don't print packet information this is useful if you're using a -z option to calculate statistics and don't want the packet information printed, just the statistics. I was in a similar situation and ended up going through tshark man pages.Ĭommand: tshark -r input_file.pcap -q -z sip,statĮxplanation: -r : Read packet data from infile I'm using tshark as i want to work with this data, and not just analyze it on my screen To clarify a bit, my idea was to get this "statistic" in tshark, like wireshark gives me when i access "Telephony>VoIP Calls" (the same way that tshark -r myfile -q -z rtp,streamsreturns me statistics just like wireshark's Telephony>RTP>Show All Streams), is there a way to do this? If not with "statistics" (-z) how can i create a filter (-R) to do something similar of the "VoIPCall" function of wireshark Tshark -r myFile -R "sip.Request-Line contains INVITE"īut i can't get the address of the server. I can retrieve some sip addrs (only client) by filtering all sip INVITE like this: What i want to know is: how can i get the sip addrs of a call? (client and server) pcap (like "source ip address and port", "destination ip addr and Port", payload pckt lost, Max Delta(ms),Max Jitter(ms),Mean Jitter(ms)) with I'm using tshark, and i can filter some important data pretty easily from the. pcap file, but later i'll be listening for this at real time. ![]()
0 Comments
Leave a Reply. |
Details
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |