LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 05-08-2012, 06:50 AM   #1
baronobeefdip
Senior Member
 
Registered: Jul 2009
Distribution: Debian Squeeze
Posts: 1,267

Rep: Reputation: 32
how do i get wireshark to save only the packets i have filtered


i have just ran wireshark through my network and i want to save only a specific types of packets for later analysis, this won't only make the packets found easier to find but it will also decrease the size of the capture file. can this be done if so how do you do it?
 
Old 05-08-2012, 06:54 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Did you just look? You just select the radio button in the save dialog to choose the displayed packets.
 
Old 05-08-2012, 08:08 PM   #3
baronobeefdip
Senior Member
 
Registered: Jul 2009
Distribution: Debian Squeeze
Posts: 1,267

Original Poster
Rep: Reputation: 32
I have just saved the filtered packets that i was after and when i opened the file in wireshark and all of the packets that i was going to examine were mal-formed.

i am running wireshark to capture jpeg files across the network for experimental purposes and when i saved the file with only the viewed packets to be saved it malformed the pictures before i could even try to re-compile them. if it is possible can you apply a filter that will collect only the packets from the filter without capturing everything since saving the filetered file makes the pictures malformed i want to see if wireshark can only capture specific packets so i can save them as normal and only have the picture files
 
Old 05-08-2012, 09:30 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by baronobeefdip View Post
i am running wireshark to capture jpeg files
Wireshark requires an X server, a Desktop Environment and all dependencies. To capture traffic you don't need that. Try the command line equivalent tshark, rawshark or tcpdump with a BPF filter if you're losing data due to fragmentation or capture performance or try tcpxtract.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Google and services problems: timeout and filtered packets hknoener Linux - Server 11 03-28-2012 05:44 AM
How do I DROP filtered packets on a Cisco router enyawix Linux - Networking 5 06-24-2011 01:26 AM
how can i configure my overseas squid server packets NOT be filtered by the local ISP hemi_426 Linux - Server 5 09-23-2009 02:30 AM
How to check if packets/ports are being filtered/blocked mfeoli Linux - Networking 1 11-05-2004 05:27 AM
IPCop - filtered packets? Sir.Del Linux - Networking 1 08-15-2003 10:11 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 03:06 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration