

In the case where no filter is given after the “io,phs” option, the statistics will be calculated for all the packets in the scope. Using the TShark we can create a Protocol based Hierarchy Statistics listing the number of packets and bytes using the “io,phs” option in the “-z” parameter. This gives us an exhaustive list of various supported formats as shown in the image given below. Initially, to learn about all the different options inside the “-z” parameter, we will be running the TShark with the “-z” parameter followed by the help keyword. To accomplish this, we will be using the “-z” parameter with TShark. TShark collects different types of Statistics and displays their result after finishing the reading of the captured file. We will understand different ways in which we can sort our traffic capture so that we can analyse it faster and effectively. In this part, we will the Statistical Functionalities of TShark.

In the previous article, we learned about the basic functionalities of this wonderful tool called TShark.
