Wireshark-users: [Wireshark-users] Batch "Copy Bytes ( Printable text only)" on marked packets?
From: Kervin Pierre <kervin@xxxxxxxxxxxx>
Date: Sat, 5 Jun 2010 05:21:28 -0700

Hello,

 

I’ve used Wireshark to dump a large HTTP session ( 1000s of requests ) that I need to process.  This worked perfectly, thanks!

 

While processing the stream, I notice that most of the lines that I needed began with the word “[ truncated ]” and was indeed cut off.  I’ve learnt that there is a 240 character limit in the GUI display ( “clist”? ) and somehow that is also enforced in text export ( can’t imagine why though ).

 

Right-clicking a packet then selecting “copy” then the “Bytes ( Printable text only)” submenu does exactly what I need.  The problem is that I  have 1000s of packets and this process will have to be done on a regular basis.  Hence I really can’t right and copy then past each packet in the capture.

 

Is there a way I can “batch copy” marked packets?

 

I really need the complete packets in the HTTP stream.

 

Is there another way I can get the complete HTTP stream?  I’m imagining this is a common thing to do.

 

Best regards,

Kervin

 

Adevsoft Web Development

http://adevsoft.com/