Convert PCAP to CSV
Extract selected packet fields from PCAP or PCAPNG into a usable CSV table.
Make CSV files online
We can't read PCAP files yet, so this conversion isn't available. If you can export your work to one of these formats - or others - we'll turn it into CSV:
How to convert pcap to csv file
- Internet
- No ratings yet.
A packet-analysis program, spreadsheet, or reporting system may require captured traffic as rows and columns instead of a binary capture. Exporting selected packet fields to CSV makes them easier to filter, edit, archive, and import into Excel, LibreOffice Calc, Python, R, or a database.
What the PCAP format is
PCAP is a binary network-capture format containing packet records, timestamps, captured and original lengths, link-layer type, and captured bytes when available. Wireshark, TShark, tcpdump, dumpcap, monitoring appliances, and intrusion-detection systems can create PCAP files; the related PCAPNG format is also common.
Network analysts use captures to troubleshoot connections, investigate security incidents, verify application behavior, and reconstruct network activity. Captures may contain credentials, IP addresses, cookies, messages, and other sensitive payloads.
What the CSV format is
CSV is plain text organized as records and separated fields. It is supported by spreadsheet applications, scripting languages, statistical tools, SQL import utilities, and reporting systems.
CSV works well for packet summaries such as frame number, timestamp, source and destination addresses, ports, protocol, and packet length. It is not a full-fidelity replacement for PCAP: raw packet bytes, protocol hierarchy, reassembly state, comments, capture metadata, and many expert-analysis details do not map reliably to a flat table. CSV also has no universal delimiter, encoding, or data-type standard, so quoting and import settings matter.
Using Wireshark
- Open the file with File → Open. Wireshark can read both PCAP and PCAPNG when supported by the installed version.
- Apply a display filter if needed, such as
dns,http, orip.addr == 192.0.2.10. Exporting packet dissections after filtering exports the packets currently shown. - Choose File → Export Packet Dissections → As CSV.
- Save the result with a
.csvextension and check the generated file before importing it.
The Wireshark CSV export is based on packet-list columns rather than a complete representation of every dissected field. Add, remove, or reorder columns through Edit → Preferences → Appearance → Columns before exporting; menu names can vary slightly by version.
Using TShark for selected fields
TShark is Wireshark's command-line analyzer and is installed with many Wireshark packages. It provides repeatable field selection and is suitable for scripts and batch processing:
tshark -r input.pcap -n -T fields -E header=y -E separator=, -E quote=d -E occurrence=f -e frame.number -e frame.time_epoch -e ip.src -e ip.dst -e tcp.srcport -e tcp.dstport -e _ws.col.protocol -e frame.len > output.csv
Replace input.pcap with the capture filename. The command disables name resolution, writes a header row, uses commas, quotes field values, and exports the first occurrence of each requested field. Fields that do not apply to a packet are blank. Add protocol-specific fields such as dns.qry.name, http.request.method, or tcp.stream with additional -e options.
To export only packets matching a display filter, add -Y:
tshark -r input.pcap -n -Y "dns or tcp.port == 443" -T fields -E header=y -E separator=, -E quote=d -E occurrence=f -e frame.number -e frame.time_epoch -e ip.src -e ip.dst -e _ws.col.protocol -e frame.len > filtered.csv
Use tshark -G fields to inspect field names available in the installed version. Do not add -F pcapng for CSV output; that option concerns capture-format output, not field export.
Quality and compatibility limits
- A capture made with a short snap length may contain complete headers but truncated payloads; CSV cannot restore missing bytes.
- Encrypted traffic normally yields addresses, ports, timestamps, and protocol metadata, not decrypted application content.
- Fields with multiple values require a deliberate policy.
-E occurrence=fkeeps only the first value; other occurrence settings can produce repeated or separator-joined values that may not fit a strict database schema. frame.time_epochprovides a numeric Unix timestamp that is less vulnerable to locale changes. Human-readable timestamp fields depend on analyzer settings and import software.- Spreadsheet programs may reinterpret timestamps, long numbers, IP addresses, and leading zeros. Import columns with explicit text, integer, or date types when exact values matter.
- Retain the original PCAP or PCAPNG as evidence and export CSV as a derived summary. CSV does not preserve enough information for reliable packet reanalysis.
Online conversion
There is no widely established online service that reliably reproduces TShark or Wireshark field dissection for arbitrary PCAP files. General file-conversion websites may reject PCAP, expose only a limited field set, or mishandle sensitive traffic. Use local Wireshark or TShark for captures containing credentials, private addresses, customer data, or forensic evidence. An online service is suitable only for a small, sanitized, non-sensitive capture after verifying that it explicitly supports PCAP-to-CSV field extraction, its retention policy, and the resulting columns.
PCAP vs CSV: format comparison
How the PCAP and CSV formats compare on the properties that matter most for this conversion.
| Property | .PCAP Packet Capture | .CSV Comma-Separated Values |
|---|---|---|
| Open standard | Partly open | Yes |
| Compression | Uncompressed | Uncompressed |
| Typical file size | Medium | Small |
| Opens in a web browser | No | Yes, natively |
| Further editing | Limited | Easy |
| Metadata support | Basic | Basic |
| Plain-text readable | No | Yes |
| Best used for | Data exchange | Data exchange |
| Introduced | 1990 | — |
| Developer | The Tcpdump group / The Wireshark Foundation (common tools and ecosystem) | — |
| MIME type | application/vnd.tcpdump.pcap | text/csv |