Convert pcap to csv

Convert PCAP to CSV

Extract selected packet fields from PCAP or PCAPNG into a usable CSV table.

Make CSV files online

We can't read PCAP files yet, so this conversion isn't available. If you can export your work to one of these formats - or others - we'll turn it into CSV:

How to convert pcap to csv file

A packet-analysis program, spreadsheet, or reporting system may require captured traffic as rows and columns instead of a binary capture. Exporting selected packet fields to CSV makes them easier to filter, edit, archive, and import into Excel, LibreOffice Calc, Python, R, or a database.

What the PCAP format is

PCAP is a binary network-capture format containing packet records, timestamps, captured and original lengths, link-layer type, and captured bytes when available. Wireshark, TShark, tcpdump, dumpcap, monitoring appliances, and intrusion-detection systems can create PCAP files; the related PCAPNG format is also common.

Network analysts use captures to troubleshoot connections, investigate security incidents, verify application behavior, and reconstruct network activity. Captures may contain credentials, IP addresses, cookies, messages, and other sensitive payloads.

What the CSV format is

CSV is plain text organized as records and separated fields. It is supported by spreadsheet applications, scripting languages, statistical tools, SQL import utilities, and reporting systems.

CSV works well for packet summaries such as frame number, timestamp, source and destination addresses, ports, protocol, and packet length. It is not a full-fidelity replacement for PCAP: raw packet bytes, protocol hierarchy, reassembly state, comments, capture metadata, and many expert-analysis details do not map reliably to a flat table. CSV also has no universal delimiter, encoding, or data-type standard, so quoting and import settings matter.

Using Wireshark

  1. Open the file with File → Open. Wireshark can read both PCAP and PCAPNG when supported by the installed version.
  2. Apply a display filter if needed, such as dns, http, or ip.addr == 192.0.2.10. Exporting packet dissections after filtering exports the packets currently shown.
  3. Choose File → Export Packet Dissections → As CSV.
  4. Save the result with a .csv extension and check the generated file before importing it.

The Wireshark CSV export is based on packet-list columns rather than a complete representation of every dissected field. Add, remove, or reorder columns through Edit → Preferences → Appearance → Columns before exporting; menu names can vary slightly by version.

Using TShark for selected fields

TShark is Wireshark's command-line analyzer and is installed with many Wireshark packages. It provides repeatable field selection and is suitable for scripts and batch processing:

tshark -r input.pcap -n -T fields -E header=y -E separator=, -E quote=d -E occurrence=f -e frame.number -e frame.time_epoch -e ip.src -e ip.dst -e tcp.srcport -e tcp.dstport -e _ws.col.protocol -e frame.len > output.csv

Replace input.pcap with the capture filename. The command disables name resolution, writes a header row, uses commas, quotes field values, and exports the first occurrence of each requested field. Fields that do not apply to a packet are blank. Add protocol-specific fields such as dns.qry.name, http.request.method, or tcp.stream with additional -e options.

To export only packets matching a display filter, add -Y:

tshark -r input.pcap -n -Y "dns or tcp.port == 443" -T fields -E header=y -E separator=, -E quote=d -E occurrence=f -e frame.number -e frame.time_epoch -e ip.src -e ip.dst -e _ws.col.protocol -e frame.len > filtered.csv

Use tshark -G fields to inspect field names available in the installed version. Do not add -F pcapng for CSV output; that option concerns capture-format output, not field export.

Quality and compatibility limits

  • A capture made with a short snap length may contain complete headers but truncated payloads; CSV cannot restore missing bytes.
  • Encrypted traffic normally yields addresses, ports, timestamps, and protocol metadata, not decrypted application content.
  • Fields with multiple values require a deliberate policy. -E occurrence=f keeps only the first value; other occurrence settings can produce repeated or separator-joined values that may not fit a strict database schema.
  • frame.time_epoch provides a numeric Unix timestamp that is less vulnerable to locale changes. Human-readable timestamp fields depend on analyzer settings and import software.
  • Spreadsheet programs may reinterpret timestamps, long numbers, IP addresses, and leading zeros. Import columns with explicit text, integer, or date types when exact values matter.
  • Retain the original PCAP or PCAPNG as evidence and export CSV as a derived summary. CSV does not preserve enough information for reliable packet reanalysis.

Online conversion

There is no widely established online service that reliably reproduces TShark or Wireshark field dissection for arbitrary PCAP files. General file-conversion websites may reject PCAP, expose only a limited field set, or mishandle sensitive traffic. Use local Wireshark or TShark for captures containing credentials, private addresses, customer data, or forensic evidence. An online service is suitable only for a small, sanitized, non-sensitive capture after verifying that it explicitly supports PCAP-to-CSV field extraction, its retention policy, and the resulting columns.

PCAP vs CSV: format comparison

How the PCAP and CSV formats compare on the properties that matter most for this conversion.

Comparison of the PCAP and CSV file formats
Property .PCAP Packet Capture .CSV Comma-Separated Values
Open standard Partly open Yes
Compression Uncompressed Uncompressed
Typical file size Medium Small
Opens in a web browser No Yes, natively
Further editing Limited Easy
Metadata support Basic Basic
Plain-text readable No Yes
Best used for Data exchange Data exchange
Introduced 1990 —
Developer The Tcpdump group / The Wireshark Foundation (common tools and ecosystem) —
MIME type application/vnd.tcpdump.pcap text/csv

Additional formats for
pcap file conversion

Reverse conversion

Convert to csv from
other formats

Share on social media: