Help answer threads with 0 replies.
Go Back > Forums > Linux Forums > Linux - Newbie
User Name
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!


  Search this Thread
Old 04-21-2010, 08:24 PM   #1
Registered: Feb 2010
Posts: 40

Rep: Reputation: 15
Tshark truncated output

I'm doing the following code in the hopes of reconstructing web pages from network traffic:

 sudo tshark -V -f "tcp port 80" > ./capfile
However, what's plaguing me is that under the section "Line-based text data: text/html," I am consistently seeing "[truncated]" at the start of each line.

Line-based text data: text/html
    [truncated] <!doctype html><html onmousemove="google&&google.fade&&google.fade(event)"><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><title>Google</title><script>{kEI:"EKTPS661KJHbnAew0tBm",kEXPI:"1
What am I doing wrong? After each line, it's cutting out key pieces of data after certain points.

I can't find pertinent information in the man pages or online for this. I can't be the first to ask this question, surely, but I am at a loss for how to rectify this issue.

Ideally, I'd like to be able to piece together the full, unadulterated web page that was passed along on the network. Has anyone dealt with such an issue?
Old 04-21-2010, 08:40 PM   #2
Registered: Apr 2002
Location: in a fallen world
Distribution: slackware by choice, others too :} ... android.
Posts: 23,067
Blog Entries: 11

Rep: Reputation: 911Reputation: 911Reputation: 911Reputation: 911Reputation: 911Reputation: 911Reputation: 911Reputation: 911
man tshark

Old 04-21-2010, 09:57 PM   #3
Registered: Feb 2010
Posts: 40

Original Poster
Rep: Reputation: 15
Thanks for the help but the -s snaplen specification it doesn't seem to be working correctly. I'd assume that it would capture the whole packet, but somewhere between capturing and displaying, it still truncates the output.

As with tcpdump, I was just doing tshark -s0, should be the same thing, unfortunately not even this works. Still gives me that "[truncated]" message under "Line-based text data: text/html".
Old 04-27-2010, 12:14 AM   #4
Registered: Feb 2010
Posts: 40

Original Poster
Rep: Reputation: 15
Could someone please verify that this isn't a problem on my end? I appear to be doing everything correctly.

I know it's always an option for me to go to Wireshark, but there's got to be a fix somehow for this issue. The "[truncated]" message is still showing up under the same section (mentioned above).

I've scoured the net for solutions to this problem but I've hit a dead end. If a guru might be able to spare a minute or two, I'd definitely appreciate it; not getting anywhere by myself.


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Tshark command hsnasi Linux - Software 2 01-20-2010 04:11 PM
tshark output to file noir911 Linux - Server 1 03-25-2009 06:17 AM
can i logged output of tshark as bin file? Barq Linux - General 3 03-03-2008 06:56 AM
Truncated 'last' output, please help! Hackeron Linux - General 1 01-04-2004 08:34 AM
Output truncated when using pipe tells Linux - General 1 12-16-2003 08:06 PM > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 04:28 PM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration