Convert PCAP to TXT
Export PCAP or PCAPNG packet details to searchable TXT with Wireshark, TShark, or tcpdump.
Make TXT files online
We can't read PCAP files yet, so this conversion isn't available. If you can export your work to one of these formats - or others - we'll turn it into TXT:
How to convert pcap to txt file
- Internet
- No ratings yet.
A support team may need a readable packet report for a ticket, email, or text-processing workflow, while the recipient may not have packet-analysis software. Exporting a capture to TXT creates searchable text, but it does not preserve the original capture for later analysis.
What the PCAP format is
PCAP stores captured network packets with timestamps, a link-layer type, packet lengths, and the captured bytes. The .pcap format is associated with libpcap; .pcapng is a newer format that can store multiple interfaces, comments, name-resolution data, and other metadata. A capture may contain only part of each packet when a capture-length limit was used.
Wireshark, TShark, tcpdump, and network-monitoring appliances can create or read these files. Network administrators, incident responders, developers, and support engineers use captures to troubleshoot connections, inspect protocols, investigate suspicious traffic, and reproduce application problems. A PCAP contains raw traffic, not necessarily protocol names or decoded fields; those are produced by an analyzer during export.
What TXT provides
TXT is a plain-text container with no required schema. An export can contain packet numbers, timestamps, addresses, protocol fields, decoded payload text, or hexadecimal bytes, depending on the selected tool and options. Text is easy to search, edit, attach, process with scripts, and open without packet-analysis software.
TXT does not inherently preserve packet indexes, protocol structure, capture metadata, or an encoding. A verbose text or hexadecimal export can be larger than the PCAP, while a selected-field export can be much smaller. Keep the original capture when exact bytes, filtering, re-dissection, or forensic verification may be required.
Using Wireshark
- Open the
.pcapor.pcapngfile in Wireshark. - Apply a display filter if the output should contain selected traffic, such as
http,ip.addr == 192.0.2.10, ortcp.port == 443. - Choose File → Export Packet Dissections → As Plain Text.
- In the export dialog, select all captured packets or only displayed packets, choose the required packet-summary, protocol-detail, and packet-byte options, and save the result with a
.txtextension.
Wireshark is the practical choice when you need to inspect packets before exporting them or control how much of the protocol tree appears in the text. The exact menu labels and export options can vary slightly by Wireshark version.
Using TShark
TShark is Wireshark's command-line analyzer and is suited to repeatable exports. Install Wireshark or its command-line package first, then run the following from PowerShell, Command Prompt, or a Linux shell:
tshark -r capture.pcap -n -V > capture.txt
-r reads the capture, -n disables address and port name resolution for consistent output, -V prints detailed protocol dissection, and > redirects the report to a text file. TShark also reads .pcapng files; substitute that filename as needed.
For a compact, script-friendly table, export selected fields instead of the full protocol tree:
tshark -r capture.pcap -n -T fields -E header=y -E separator=, -E quote=d -e frame.number -e frame.time -e ip.src -e ip.dst -e _ws.col.Protocol -e _ws.col.Info > capture.txt
This produces comma-separated text inside a TXT file; use a spreadsheet or script that understands CSV if the fields must be processed as columns. Export only matching displayed packets with:
tshark -r capture.pcap -n -Y "dns or http" -V > capture.txt
To include captured packet bytes in hexadecimal and ASCII form, use:
tshark -r capture.pcap -n -x > capture.txt
A display filter such as -Y is applied while reading an existing capture. A capture filter cannot be applied retroactively; it must be specified during live capture.
Using tcpdump
For a quick human-readable dump without Wireshark's full protocol tree, use:
tcpdump -nn -X -r capture.pcap > capture.txt
-nn prevents hostname and service-name lookups, -X prints packet data in hexadecimal with an ASCII view, and -r reads the existing capture. tcpdump's output is useful for summaries and raw-byte inspection, but TShark or Wireshark generally provides more complete protocol dissection.
Online conversion and privacy
There is no generally recommended generic online converter for PCAP-to-TXT exports. Many file-conversion sites do not decode packets, and uploading a capture can disclose credentials, cookies, internal addresses, private messages, or malware samples. Use Wireshark, TShark, or tcpdump locally.
For a deliberately sanitized, non-sensitive sample, an online service is acceptable only if it explicitly supports PCAP or PCAPNG dissection, documents retention and deletion, and provides the required export fields. A service that merely changes the filename extension or treats the capture as an arbitrary binary file has not performed a meaningful conversion.
Quality and compatibility limits
- Output depends on the analyzer version, enabled dissectors, link-layer type, packet truncation, and available protocol context.
- Encrypted traffic remains encrypted unless the analyzer has the appropriate keys and configuration, such as TLS key logs or IPsec secrets.
- Malformed, fragmented, or incomplete packets may produce partial or different dissections between tool versions.
- Payloads can contain binary data and non-printable characters; use hexadecimal output when exact captured bytes matter.
- Text exports can contain sensitive data and should receive the same access controls as the original capture.
- A TXT export normally cannot be imported back into Wireshark as a usable PCAP. Retain the original file for reanalysis.
- For large captures, filter packets or export selected fields to prevent an unwieldy report. Verbose and hexadecimal modes can produce very large files.
PCAP vs TXT: format comparison
How the PCAP and TXT formats compare on the properties that matter most for this conversion.
| Property | .PCAP Packet Capture | .TXT Plain Text File |
|---|---|---|
| Open standard | Partly open | Yes |
| Compression | Uncompressed | Uncompressed |
| Typical file size | Medium | Very small |
| Opens in a web browser | No | Yes, natively |
| Further editing | Limited | Easy |
| Metadata support | Basic | None |
| Plain-text readable | No | Yes |
| Best used for | Data exchange | Data exchange |
| Introduced | 1990 | — |
| Developer | The Tcpdump group / The Wireshark Foundation (common tools and ecosystem) | — |
| MIME type | application/vnd.tcpdump.pcap | text/plain |