skip to content

On a headless host, how do you get Wireshark's Conversations, Protocol Hierarchy and Expert Info summaries from tshark 4.6, and why doesn't -Y narrow them?

level: middleimportance: nice to knowfreq 9%

answer

  1. statistics after the read
  2. one -z per table
  3. -q silences per-packet lines
  4. each tap takes its own filter
  5. exact bytes need a preference

basics

~10 s

Use tshark -r file -q with one -z per summary: conv,tcp, endpoints,ip, io,phs, expert. Each -z table ignores the main -Y display filter and takes its own optional filter argument, such as -z conv,tcp,ip.addr==192.0.2.10.

solid answer

~40 s

`tshark -r capture.pcapng -q -z io,phs -z conv,tcp -z endpoints,ip -z expert,warn` prints Protocol Hierarchy, the TCP conversation table (sorted by total frames), endpoints and Warn-and-higher expert items after reading the file; `-q` suppresses the per-packet lines. The man page says statistics are **calculated independently of the main display filter**: `-Y` only decides which packets are printed or written. To narrow a table, put the filter in the tap itself, as in `-z conv,tcp,ip.addr==192.0.2.10` or `-z expert,note,tcp`. `-z io,stat,1,tcp.analysis.retransmission` gives a per-second count, and `-z smb2,srt` the SMB2 response times. In 4.6, byte counts in `-z conv` and `-z endpoints` are SI-prefixed unless you set `-o conv.machine_readable:TRUE`.

code

bash · 6 lines
bash
tshark -r slow-app.pcapng -q -o conv.machine_readable:TRUE \
  -z io,phs \
  -z conv,tcp,ip.addr==192.0.2.10 \
  -z endpoints,ip \
  -z expert,warn,tcp \
  -z io,stat,1,tcp.analysis.retransmission,tcp.analysis.zero_window

go deeper

for a junior

Recall that tshark prints Wireshark's statistics with -z after reading a file, and that -q keeps the per-packet lines out of the way.

for a middle

Explain the main taps (io,phs, conv, endpoints, expert, io,stat), their filter argument, and why the main -Y filter does not change them.

for a senior

Show you can script a repeatable triage: tap filters per host or stream, io,stat columns for analysis flags, exact counts via the 4.6 preference, and the sequence-analysis preference left on.

for a principal

Treat the command lines as part of the evidence: a team standard for which -z tables accompany an incident capture makes results comparable between analysts and runs.

## Why tshark for statistics **tshark** is Wireshark's command-line twin: the same dissectors, the same preferences, no GUI. On a server, a jump host or a CI job that has to summarise a capture, its `-z` option prints the same statistics the Statistics and Analyze menus show, as plain text you can paste into a ticket or diff between two runs. ## The -z statistics that mirror the GUI | GUI window | tshark | Output | |---|---|---| | Statistics > Protocol Hierarchy | `-z io,phs[,filter]` | protocol tree with frames and bytes | | Statistics > Conversations | `-z conv,type[,filter]` (type `tcp`, `udp`, `ip`, `ipv6`, `eth`, ...) | one line per conversation, frames and bytes each way, total, relative start, duration; sorted by total frames | | Statistics > Endpoints | `-z endpoints,type[,filter]` | one line per endpoint, packets and bytes in each direction; sorted by total packets | | Analyze > Expert Info | `-z expert[,error|,warn|,note|,chat|,comment][,filter]` | expert items grouped by severity, at or above the level given | | Statistics > I/O Graphs | `-z io,stat,interval[,filter]...` | packets and bytes per interval, one column per filter; `COUNT()`, `SUM()`, `MIN()`, `MAX()`, `AVG()`, `LOAD()` for fields | | Statistics > Service Response Time | `-z smb2,srt`, `-z snmp,srt` and other per-protocol `srt` taps | per-operation response-time statistics | `-z help` lists every statistic this build supports. A typical first pass over a capture of a slow application: ```bash tshark -r slow-app.pcapng -q -z io,phs -z conv,tcp -z expert,warn ``` ## Why -Y does not narrow them This surprises people who use `-Y` every day. The tshark manual states that statistics are **calculated independently of the normal per-packet output and unaffected by the main display filter**. `-Y` decides which packets are printed or written to a file; the `-z` taps still see every packet that was read. Three things do narrow a `-z` table: 1. **the tap's own filter argument**, the last field in its spec: `-z conv,tcp,ip.addr==192.0.2.10` lists only conversations whose packets match; 2. a **capture filter**, when tshark is capturing live, because those packets never exist; 3. a **read filter** with `-R`, which applies in the first pass of a two-pass run (`-2`). So `tshark -r app.pcapng -q -Y 'ip.addr==192.0.2.10' -z conv,tcp` still prints every TCP conversation in the file, and the `-Y` is doing nothing useful because `-q` already suppressed the per-packet lines. ## Details that bite - **Severity floors.** `-z expert,warn` shows Warn and Error; `-z expert,note,tcp` shows Note and higher for frames containing TCP. The level is a floor, not an exact match. - **Field calculations in io,stat.** In the calculated form the field must also appear in the filter part, or the calculation fails: `-z io,stat,0.010,AVG(smb.time)smb.time` works, `AVG(smb.time)` alone does not. A field that occurs several times in a packet is counted several times. - **Interval 0.** `-z io,stat,0,...` computes one row over the whole capture, handy for totals per filter. - **Exact byte counts.** In 4.6 the `-z conv` and `-z endpoints` tables print sizes with SI prefixes by default. The Statistics preference `conv.machine_readable` switches both the GUI dialogs and these taps to exact counts: `-o conv.machine_readable:TRUE`. - **TCP analysis must be on.** `tcp.analysis.*` filters and the TCP expert items rely on the TCP preference **Analyze TCP sequence numbers**, on by default; a run with `-o tcp.analyze_sequence_numbers:FALSE` silently produces empty retransmission columns. - **Repeatable.** `-z` may be given several times in one run, so a single read of a large file produces all the tables. ## Reading the conversation table `-z conv,tcp` prints one line per conversation with frames and bytes in each direction, the totals, the relative start time and the duration. Because the table is **sorted by total frames**, the top row is the chattiest flow, not necessarily the slow one: a flow that moved little data over a long duration sits further down. Dividing bytes by duration for the rows you care about, or rerunning with a tap filter for one host, turns the table into an answer. `-z endpoints,ip` is the per-host view of the same capture, sorted by total packets. ## A practical pattern - Run the whole-file summary once: protocol hierarchy, TCP conversations, Warn-level expert items. - Pick the conversation, then rerun with tap filters for that stream or host, plus `-z io,stat,1,...` lines for `tcp.analysis.retransmission` and `tcp.analysis.zero_window` to see when trouble occurred. - Keep the command lines in the ticket so the numbers can be regenerated from the same file.

  • Why does `-z io,stat,1,AVG(smb.time)` fail while `-z io,stat,1,AVG(smb.time)smb.time` works?
    In io,stat's calculated form the filter is not optional and the field the calculation uses must appear in it. The second form names `smb.time` as the filter, so only packets carrying the field are averaged; the first has no filter, and the man page says the calculation fails.
  • You need the TCP conversation table for one host only. What do you change?
    Add the filter to the tap itself: `-z conv,tcp,ip.addr==192.0.2.10`. Adding `-Y 'ip.addr==192.0.2.10'` would only change which packets are printed or written, and the table would still list every conversation in the file.

saying these in an interview costs you the question

  • Adding -Y to a tshark command also narrows its -z statistics.
  • -z expert,warn shows only Warn items and hides Errors.
  • tshark needs a separate run for each -z table.
  • -q suppresses the -z statistics as well as the packet lines.
  • -z conv,tcp always prints exact byte counts in tshark 4.6.