Convert pcap to txt

Convert PCAP to TXT

Export PCAP or PCAPNG packet details to searchable TXT with Wireshark, TShark, or tcpdump.

Make TXT files online

We can't read PCAP files yet, so this conversion isn't available. If you can export your work to one of these formats - or others - we'll turn it into TXT:

How to convert pcap to txt file

A support team may need a readable packet report for a ticket, email, or text-processing workflow, while the recipient may not have packet-analysis software. Exporting a capture to TXT creates searchable text, but it does not preserve the original capture for later analysis.

What the PCAP format is

PCAP stores captured network packets with timestamps, a link-layer type, packet lengths, and the captured bytes. The .pcap format is associated with libpcap; .pcapng is a newer format that can store multiple interfaces, comments, name-resolution data, and other metadata. A capture may contain only part of each packet when a capture-length limit was used.

Wireshark, TShark, tcpdump, and network-monitoring appliances can create or read these files. Network administrators, incident responders, developers, and support engineers use captures to troubleshoot connections, inspect protocols, investigate suspicious traffic, and reproduce application problems. A PCAP contains raw traffic, not necessarily protocol names or decoded fields; those are produced by an analyzer during export.

What TXT provides

TXT is a plain-text container with no required schema. An export can contain packet numbers, timestamps, addresses, protocol fields, decoded payload text, or hexadecimal bytes, depending on the selected tool and options. Text is easy to search, edit, attach, process with scripts, and open without packet-analysis software.

TXT does not inherently preserve packet indexes, protocol structure, capture metadata, or an encoding. A verbose text or hexadecimal export can be larger than the PCAP, while a selected-field export can be much smaller. Keep the original capture when exact bytes, filtering, re-dissection, or forensic verification may be required.

Using Wireshark

  1. Open the .pcap or .pcapng file in Wireshark.
  2. Apply a display filter if the output should contain selected traffic, such as http, ip.addr == 192.0.2.10, or tcp.port == 443.
  3. Choose File → Export Packet Dissections → As Plain Text.
  4. In the export dialog, select all captured packets or only displayed packets, choose the required packet-summary, protocol-detail, and packet-byte options, and save the result with a .txt extension.

Wireshark is the practical choice when you need to inspect packets before exporting them or control how much of the protocol tree appears in the text. The exact menu labels and export options can vary slightly by Wireshark version.

Using TShark

TShark is Wireshark's command-line analyzer and is suited to repeatable exports. Install Wireshark or its command-line package first, then run the following from PowerShell, Command Prompt, or a Linux shell:

tshark -r capture.pcap -n -V > capture.txt

-r reads the capture, -n disables address and port name resolution for consistent output, -V prints detailed protocol dissection, and > redirects the report to a text file. TShark also reads .pcapng files; substitute that filename as needed.

For a compact, script-friendly table, export selected fields instead of the full protocol tree:

tshark -r capture.pcap -n -T fields -E header=y -E separator=, -E quote=d -e frame.number -e frame.time -e ip.src -e ip.dst -e _ws.col.Protocol -e _ws.col.Info > capture.txt

This produces comma-separated text inside a TXT file; use a spreadsheet or script that understands CSV if the fields must be processed as columns. Export only matching displayed packets with:

tshark -r capture.pcap -n -Y "dns or http" -V > capture.txt

To include captured packet bytes in hexadecimal and ASCII form, use:

tshark -r capture.pcap -n -x > capture.txt

A display filter such as -Y is applied while reading an existing capture. A capture filter cannot be applied retroactively; it must be specified during live capture.

Using tcpdump

For a quick human-readable dump without Wireshark's full protocol tree, use:

tcpdump -nn -X -r capture.pcap > capture.txt

-nn prevents hostname and service-name lookups, -X prints packet data in hexadecimal with an ASCII view, and -r reads the existing capture. tcpdump's output is useful for summaries and raw-byte inspection, but TShark or Wireshark generally provides more complete protocol dissection.

Online conversion and privacy

There is no generally recommended generic online converter for PCAP-to-TXT exports. Many file-conversion sites do not decode packets, and uploading a capture can disclose credentials, cookies, internal addresses, private messages, or malware samples. Use Wireshark, TShark, or tcpdump locally.

For a deliberately sanitized, non-sensitive sample, an online service is acceptable only if it explicitly supports PCAP or PCAPNG dissection, documents retention and deletion, and provides the required export fields. A service that merely changes the filename extension or treats the capture as an arbitrary binary file has not performed a meaningful conversion.

Quality and compatibility limits

  • Output depends on the analyzer version, enabled dissectors, link-layer type, packet truncation, and available protocol context.
  • Encrypted traffic remains encrypted unless the analyzer has the appropriate keys and configuration, such as TLS key logs or IPsec secrets.
  • Malformed, fragmented, or incomplete packets may produce partial or different dissections between tool versions.
  • Payloads can contain binary data and non-printable characters; use hexadecimal output when exact captured bytes matter.
  • Text exports can contain sensitive data and should receive the same access controls as the original capture.
  • A TXT export normally cannot be imported back into Wireshark as a usable PCAP. Retain the original file for reanalysis.
  • For large captures, filter packets or export selected fields to prevent an unwieldy report. Verbose and hexadecimal modes can produce very large files.

PCAP vs TXT: format comparison

How the PCAP and TXT formats compare on the properties that matter most for this conversion.

Comparison of the PCAP and TXT file formats
Property .PCAP Packet Capture .TXT Plain Text File
Open standard Partly open Yes
Compression Uncompressed Uncompressed
Typical file size Medium Very small
Opens in a web browser No Yes, natively
Further editing Limited Easy
Metadata support Basic None
Plain-text readable No Yes
Best used for Data exchange Data exchange
Introduced 1990 —
Developer The Tcpdump group / The Wireshark Foundation (common tools and ecosystem) —
MIME type application/vnd.tcpdump.pcap text/plain

Additional formats for
pcap file conversion

Reverse conversion

Convert to txt from
other formats

Share on social media: