![Wireshark Revealed:Essential Skills for IT Professionals](https://wfqqreader-1252317822.image.myqcloud.com/cover/399/36700399/b_36700399.jpg)
Capturing traffic with Tshark
Tshark can be used to capture network packets and/or display data from the capture or a previously saved packet trace file; packets can be displayed on the screen or saved to a new trace file.
The same syntax used to perform a basic capture using Dumpcap will work with Tshark as well, so we won't repeat that here. However, Tshark offers a very wide range of additional features, with a corresponding large number of command-line options that can, as in all Wireshark utilities, be viewed by typing tshark –h
in the command prompt.
A number of Tshark options are to view statistics; an example of the command syntax and statistical results from a capture (after pressing Ctrl + C to end the capture) is illustrated in the following screenshot:
![](https://epubservercos.yuewen.com/26AE05/19470399901599106/epubprivate/OEBPS/Images/4638OS_08_02.jpg?sign=1739298737-B6gYz8rDqml06OoXt087mGAhBzqDjOVY-0-ade610efe3dcf13b38eb16aabf68bf95)
You will find an extensive number of details and examples on using statistics and other Tshark options at https://www.wireshark.org/docs/man-pages/tshark.html.