L print list of link-layer types of iface and exit y link layer type (def: first appropriate) f packet filter in libpcap filter syntax i name or idx of interface (def: first non-loopback)
For more information on tshark see the manual pages ( man tshark). It supports the same options as wireshark. TShark is a terminal oriented version of Wireshark designed for capturing and displaying packets when an interactive user interface isn’t necessary or available. You can find more information about each command in the Manual Pages. These tools will be described in this chapter. 9. text2pcap: Converting ASCII hexdumps to network capturesĪlong with the main application, Wireshark comes with an array of command line tools which can be helpful for specialized tasks.8. mergecap: Merging multiple capture files into one.6. rawshark: Dump and analyze network traffic.5. capinfos: Print information about capture files.4. dumpcap: Capturing with dumpcap for viewing with Wireshark.