ScreenshotNeo

BlogHow-to

How to Check Network Traffic with Automation Scripts

Capture and inspect authorized network traffic with TShark, then turn packets, fields and statistics into reliable script output.

By the ScreenshotNeo team4 October 20267 min read

Use TShark to capture traffic from an authorized network interface, save a bounded capture, and analyze it with a second command. For example, capture TCP traffic on port 443 for 30 seconds, then print selected fields from the saved file:

tshark -i eth0 -f 'tcp port 443' -a duration:30 -w sample.pcapng
tshark -r sample.pcapng -Y 'tcp' -T fields -e frame.time -e ip.src -e ip.dst -e tcp.dstport

Replace eth0 with an interface shown by tshark -D. Capture filters (-f) limit packets as they are collected; display filters (-Y) select decoded packets during analysis. Their syntaxes differ. Capture only traffic you are authorized to inspect, and remember that packet capture sees traffic visible at its capture point, not automatically every packet on a switched network. The TShark manual documents these options and filter behavior.

1. Define the question and scope

Choose the evidence the script needs before capturing. A connectivity check may need timestamps and endpoints; a volume check may need packet and byte counts; a protocol investigation may need a small set of decoded fields. Record the interface, host or port, protocol, time window, output format and retention period.

  • Interface: capture occurs where the selected interface can see packets. Check the capture host and network path.
  • Filter: use a narrow capture filter when practical to reduce unnecessary collection.
  • Duration and size: bound the capture by time or packet count and ensure the destination has room.
  • Data handling: packet files can contain identifiers and, depending on protocol and encryption, payload data. Restrict access, sharing and retention.

2. Find TShark and the capture interface

TShark is Wireshark’s terminal-oriented tool. It can capture live traffic and read saved capture files, which makes it useful for repeatable scripts as well as offline analysis.

command -v tshark
tshark --version
tshark -D

On Windows, use the installed command prompt or PowerShell environment and the TShark executable installed with Wireshark. Interface names and permission setup vary by operating system. Confirm command options against the locally installed release with tshark -h or its manual; online documentation can describe options newer than the installed version.

Live capture requires sufficient privileges. Configure the least privilege needed for packet capture instead of running a long-lived monitoring script as an administrator. See the Wireshark User’s Guide and capture privileges guidance for platform-specific details.

3. Capture a bounded sample

For a short diagnostic, write packets to a file first. That creates an artifact that can be reviewed again without capturing live traffic a second time.

# Linux/macOS example; adapt interface, filter and path.
tshark -i eth0 -f 'tcp port 443' -a duration:30 -w sample.pcapng

The command captures on eth0, applies a libpcap capture filter, stops after 30 seconds, and writes pcapng output. Check the installed TShark help for accepted stop conditions and filter support. You can use dumpcap for capture-focused workflows; tcpdump is another common lightweight option, including for remote/headless capture as described in the Wireshark guide. Use Wireshark’s GUI to interactively follow up on a saved file.

Capture filter examples

Goal Capture filter
TCP port 443 tcp port 443
Traffic to or from one IPv4 host host 192.0.2.10
DNS traffic port 53
One protocol family and port udp port 53

These are examples; verify the expression for the installed capture stack and platform. Do not assume that promiscuous mode exposes all traffic on a switched LAN. Capture placement, interface configuration and network behavior determine what is visible.

4. Analyze the capture with TShark

Read the file and apply a display filter to select decoded packets. Use -T fields with explicit fields for output that a script can parse:

tshark -r sample.pcapng \
  -Y 'tcp' \
  -T fields \
  -e frame.time \
  -e ip.src \
  -e ip.dst \
  -e tcp.srcport \
  -e tcp.dstport

For DNS queries, for example, inspect only DNS packets and request relevant fields supported by the local version:

tshark -r sample.pcapng -Y 'dns' -T fields \
  -e frame.time -e ip.src -e dns.qry.name

Field availability depends on protocol dissection and version. Check the local field list or test the field against a known capture. TShark also provides statistics modes, including interval packet and byte counts; consult tshark -z help and the installed manual for supported statistics. Prefer the narrow capture filter at collection time where possible: the manual notes capture filters are more efficient, and display filtering during busy live capture can increase packet-loss risk.

Capture filters and display filters

Option When it applies Purpose
-f Capture Filter packets at collection time using capture-filter syntax.
-Y Capture display or saved-file analysis Select decoded packets using Wireshark display-filter syntax.

Do not copy a display filter into -f or assume a capture-filter expression works with -Y. TShark’s manual explains that display filters can be specified while capturing or reading a file, but the two filter languages remain distinct.

5. Turn capture output into a script result

Check the process exit status, output file and number of selected rows. A successful command that returns no packets can indicate a wrong interface, filter, time window or permission setup; it does not by itself prove that the network has no issue.

#!/usr/bin/env bash
set -u
capture=sample.pcapng

if ! tshark -i eth0 -f 'tcp port 443' -a duration:30 -w "$capture"; then
  echo "TShark capture failed" >&2
  exit 1
fi

if [ ! -s "$capture" ]; then
  echo "Capture file is missing or empty" >&2
  exit 2
fi

if ! tshark -r "$capture" -Y 'tcp' -T fields \
  -e frame.time -e ip.src -e ip.dst -e tcp.dstport; then
  echo "Capture analysis failed" >&2
  exit 3
fi

For downstream automation, select stable fields and a predictable delimiter or use a structured output format supported by your installed TShark version. Treat packet values as untrusted input: quote paths, avoid evaluating output as shell code, and account for delimiters or newlines in field values. Keep diagnostics on stderr and machine-readable results on stdout when composing a pipeline.

6. Choose the right capture workflow

Approach Best fit Trade-off
TShark live capture Quick command-line checks and decoded output Needs capture permissions; live display filtering adds work.
TShark or dumpcap to file, then TShark analysis Repeatable investigations, review and re-analysis Requires bounded storage and secure handling of capture files.
tcpdump capture, then TShark/Wireshark Lightweight or remote/headless collection Decode and analysis happen in a later step.
Wireshark GUI on saved file Interactive protocol exploration Less suited to unattended script output.

7. Reliability, performance and cost

  • Reduce capture work: a narrow capture filter and bounded interval limit the data collected. Avoid unnecessary live display filtering on a busy interface.
  • Validate the environment: check TShark version, interface, permissions, disk space, filter syntax and required fields before scheduling a job.
  • Make results interpretable: report capture duration, interface, filter, exit code and packet count alongside extracted values.
  • Handle empty and partial captures: distinguish a valid zero-match result from command failure, interrupted capture or an empty artifact.
  • Protect the data: set restrictive file permissions, limit retention and avoid uploading captures unless authorized.
  • Cost: TShark, dumpcap, tcpdump and Wireshark are software tools; this workflow does not inherently require buying monitoring hardware. Storage, compute and operational review depend on the environment.

8. Troubleshooting

Symptom Likely cause What to check
Permission denied or no capture devices The process lacks capture rights, or capture permissions are not configured. Use the platform’s Wireshark capture guidance and grant only the necessary capture privilege.
Unknown interface The interface name differs from the example or changed. Run tshark -D and use the listed interface identifier.
Zero packets Wrong interface, filter, time window, capture point or no matching traffic. Check interface and filter; do a short authorized capture with a broader filter, then narrow it.
Capture filter syntax error A display-filter expression was passed to -f, or the platform’s capture filter parser rejects it. Use capture-filter syntax and validate it against local help/manual.
Display filter error Invalid display-filter syntax or unsupported field in this version. Check the field/filter reference for the installed release and test on a saved capture.
Missing field values The packet does not contain that field, the protocol was not dissected as expected, or the field is unavailable. Inspect a sample packet and verify the field name using local TShark documentation.
Capture file cannot be read Wrong path, incomplete write, insufficient permissions or unsupported format. Check file existence and access, wait for the capture process to finish, then read the resulting file.
Packets appear to be dropped Capture load, interface constraints or expensive live display filtering may be involved. Apply a narrower capture filter, save to file for later analysis, and inspect capture statistics and host capacity.
Script works interactively but not in a scheduler Different PATH, user permissions, working directory or environment. Use explicit paths, set the working directory, log stderr and run under the intended service account.

Or skip the browser setup

For website screenshots, ScreenshotNeo is a one-request screenshot API. It does not inspect network packets or replace TShark; it captures a rendered page. The request below saves a screenshot response:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for request options. Cookie banners, popups and chat widgets are removed before the shot; bot checks, blank pages and failed loads are never billed; an MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card, and paid plans start at $5 for 3,000. Sign up for free ScreenshotNeo access.

FAQ

Can I analyze an existing pcap or pcapng file without capture privileges?

Yes. Reading a saved capture with tshark -r does not require starting a live capture, though file access and local policy still apply.

Can a packet capture prove that a server is reachable?

It can show packets visible at the capture point, such as requests and responses. Combine that evidence with the actual application result and the network path; absence of a packet can also mean the capture point or filter missed it.

Should a scheduled script keep one capture file forever?

No. Set a retention period and access controls appropriate to the sensitivity of the data, and rotate or remove files when they are no longer needed.