Table of Contents
Overview
TShark is the command-line version of Wireshark, providing powerful network protocol analysis capabilities without a GUI interface.
Key Features
- Live packet capture
- Capture file reading
- Protocol analysis
- Advanced filtering
- Multiple output formats
- Statistics generation
- Decryption support
- Remote capture
Installation
Ubuntu (22.04/24.04)
macOS
Basic Usage
Basic Capture
Reading Files
Capture Filters
Protocol Filters
Host Filters
Combined Filters
Display Filters
Protocol Analysis
Connection States
Application Layer
Field Selection
Statistics
Packet Details
Advanced Features
Decryption
Remote Capture
Ring Buffer
Analysis Techniques
Traffic Analysis
Security Analysis
Best Practices
Capture Management
Analysis Tips
Quick Reference
Essential Commands
Common Options
Remember:
- Consider capture file size
- Use appropriate filters
- Monitor system resources
- Secure sensitive data
- Regular cleanup of captures
- Document analysis findings
For detailed information, consult the man pages (man tshark
).