Wireshark Q&A I then expected to see the actual traffic, but this was not the case. Wireshark, in fact, can read those .cap file but is not … file tcpdump抓包写入文件参数应该用 -w 而不是 > 例如: tcpdump -i eth0 src host 192.168.1. tcpdump抓包写入文件参数应该用 -w 而不是 > 例如: tcpdump -i eth0 src host 192.168.1. I need to capture some traffic using Microsoft Network Monitor because I need to select only some process ids. Where Wireshark responds to opening the file "The file "xxxxx" isn't a capture file in a format wireshark understands. In the packet detail, closes all tree items. 4.8. It has been working fine. However, when I type this command: tshark -r udp.pcap -T pdml >temp.pdml I got this error: tshark: The file "udp.pcap" isn't a capture file in a format TShark understands. Hi, I am using an EL3 machine and would like to translate some pcap files into pdml format. How to save pcap file to text file using tshark - Stack Overflow tshark -F {output file format} -r {input file} -w {output file} so, if you want to read the pcap file and write it out as a "K12 text format" file, you can do it with. tshark -i eth -b duration:10 -x > trial.txt. However, when I type this command: tshark -r udp.pcap -T pdml >temp.pdml I got this error: tshark: The file "udp.pcap" isn't a capture file in a format TShark understands. Table of Contents. How was the file captured on that machine? Capture files and file modes. Sniff Wireless Packets with Wireshark