Wireshark provides several ways and formats to export packet data. This section describes general ways to export data from Wireshark.
Note! | |
---|---|
There are more specialized functions to export specific data, which will be described at the appropriate places. |
XXX - add detailed descriptions of the output formats and some sample output, too.
Export packet data into a plain ASCII text file, much like the format used to print packets.
-
Export to file: frame chooses the file to export the packet data to.
-
The Packet Range frame is described in Section 5.9, “The Packet Range frame”.
-
The Packet Details frame is described in Section 5.10, “The Packet Format frame”.
Export packet data into PostScript, much like the format used to print packets.
Tip! | |
---|---|
You can easily convert PostScript files to PDF files using ghostscript. For example: export to a file named foo.ps and then call: ps2pdf foo.ps |
-
Export to file: frame chooses the file to export the packet data to.
-
The Packet Range frame is described in Section 5.9, “The Packet Range frame”.
-
The Packet Details frame is described in Section 5.10, “The Packet Format frame”.
XXX - add screenshot
Export packet summary into CSV, used e.g. by spreadsheet programs to im-/export data.
-
Export to file: frame chooses the file to export the packet data to.
-
The Packet Range frame is described in Section 5.9, “The Packet Range frame”.
XXX - add screenshot
Export packet bytes into C arrays so you can import the stream data into your own C program.
-
Export to file: frame chooses the file to export the packet data to.
-
The Packet Range frame is described in Section 5.9, “The Packet Range frame”.
Export packet data into PSML. This is an XML based format including only the packet summary. The PSML file specification is available at: http://www.nbee.org/doku.php?id=netpdl:psml_specification.
-
Export to file: frame chooses the file to export the packet data to.
-
The Packet Range frame is described in Section 5.9, “The Packet Range frame”.
There's no such thing as a packet details frame for PSML export, as the packet format is defined by the PSML specification.
Export packet data into PDML. This is an XML based format including the packet details. The PDML file specification is available at: http://www.nbee.org/doku.php?id=netpdl:pdml_specification.
The PDML specification is not officially released and Wireshark's implementation of it is still in an early beta state, so please expect changes in future Wireshark versions. |
-
Export to file: frame chooses the file to export the packet data to.
-
The Packet Range frame is described in Section 5.9, “The Packet Range frame”.
There's no such thing as a packet details frame for PDML export, as the packet format is defined by the PDML specification.
Export the bytes selected in the "Packet Bytes" pane into a raw binary file.
-
Name: the filename to export the packet data to.
-
The Save in folder: field lets you select the folder to save to (from some predefined folders).
-
Browse for other folders provides a flexible way to choose a folder.
This feature scans through HTTP streams in the currently open capture file or running capture and takes reassembled objects such as HTML documents, image files, executables and anything else that can be transferred over HTTP and lets you save them to disk. If you have a capture running, this list is automatically updated every few seconds with any new objects seen. The saved objects can then be opened with the proper viewer or executed in the case of executables (if it is for the same platform you are running Wireshark on) without any further work on your part. This feature is not available when using GTK2 versions below 2.4.
Columns:
-
Packet num: The packet number in which this object was found. In some cases, there can be multiple objects in the same packet.
-
Hostname: The hostname of the server that sent the object as a response to an HTTP request.
-
Content Type: The HTTP content type of this object.
-
Bytes: The size of this object in bytes.
-
Filename: The final part of the URI (after the last slash). This is typically a filename, but may be a long complex looking string, which typically indicates that the file was received in response to a HTTP POST request.
Buttons:
-
Help: Opens this section in the user's guide.
-
Close: Closes this dialog.
-
Save As: Saves the currently selected object as a filename you specify. The default filename to save as is taken from the filename column of the objects list.
-
Save All: Saves all objects in the list using the filename from the filename column. You will be asked what directory / folder to save them in. If the filename is invalid for the operating system / file system you are running Wireshark on, then an error will appear and that object will not be saved (but all of the others will be).