Convert pcapng to txt

Convert PCAPNG to TXT

Export PCAPNG captures as readable packet summaries or protocol dissections in TXT format.

Make TXT files online

We can't read PCAPNG files yet, so this conversion isn't available. If you can export your work to one of these formats - or others - we'll turn it into TXT:

How to convert pcapng to txt file

Network-analysis tools produce PCAPNG captures, while ticketing systems, scripts, and basic document workflows may accept only plain TXT files. Exporting the capture creates a readable packet summary or protocol dissection, but it does not preserve the original file for later packet analysis.

What the PCAPNG format is

PCAPNG (Packet Capture Next Generation) is a binary container for recorded network traffic. It can store packet bytes, timestamps, interface information, comments, name-resolution data, and traffic captured through multiple interfaces.

Wireshark, tshark, tcpdump-based utilities, network appliances, intrusion-detection systems, and operating-system capture tools can create or read PCAPNG files. PCAPNG commonly appears after connection troubleshooting, incident investigation, application-traffic analysis, or a Wireshark capture.

What the TXT format is

TXT contains plain character data that text editors, command-line utilities, scripts, ticketing systems, and document-management software can process. A PCAPNG export can contain a packet list, selected protocol fields, or a complete human-readable protocol dissection.

TXT is useful for searching with tools such as grep, comparing reports, attaching readable evidence to a ticket, and extracting selected metadata. It does not preserve the original packet structure, interface blocks, packet indexes, or raw packet bytes unless those details are explicitly written to the export.

How to convert PCAPNG to TXT

Using Wireshark

  1. Open the .pcapng file in Wireshark.
  2. Apply a display filter if the export should contain only matching traffic, such as dns, http, or ip.addr == 192.0.2.10.
  3. Choose File → Export Packet Dissections → As Plain Text.
  4. In the export dialog, choose all packets or only displayed packets, select the required packet-detail level, and save the output with a .txt extension.

Exporting only displayed packets excludes traffic hidden by the display filter. Use the full-detail option when the recipient needs protocol fields and payload dissection; use a summary or lower-detail option for a smaller report.

Using tshark

tshark is Wireshark's command-line analyzer and is suitable for repeatable exports and large captures. To write a verbose protocol dissection:

tshark -r capture.pcapng -V > capture.txt

To export only packets selected by a display filter:

tshark -r capture.pcapng -Y "dns or http" -V > selected-packets.txt

For a compact, script-friendly text file containing selected fields:

tshark -r capture.pcapng -T fields -E header=y -E separator=, -E quote=d -E escape=y -e frame.number -e frame.time -e ip.src -e ip.dst -e _ws.col.Protocol -e _ws.col.Info > packet-fields.txt

The fields export is delimited text rather than a formally standardized CSV file; use a CSV-aware parser and select an appropriate separator if field values may contain commas. Shell redirection preserves the command's output encoding and line endings, which can vary with the operating system and locale.

Using an online converter

Online services such as CloudConvert can be considered only when their current format list explicitly supports .pcapng as input and TXT as output. Such services may generate a generic text dump rather than the packet dissection produced by Wireshark or tshark. Do not upload confidential captures: packet payloads can contain credentials, tokens, personal data, internal addresses, and proprietary content. Check retention and deletion policies before using any service; Wireshark and tshark are safer choices for sensitive traffic.

Quality and compatibility limits

PCAPNG-to-TXT has no single standardized output. A packet summary, selected fields, and full protocol dissection are different representations, so confirm which one the receiving application requires.

Keep the original PCAPNG file as the analyzable or evidentiary copy. TXT cannot normally support later packet filtering, stream reconstruction, packet reassembly, or protocol analysis. Decryption also requires the original capture and any required keys or secrets.

Verbose output can be much larger than the source capture. Use a display filter, selected fields, or a packet range to control size, and verify that packet numbers, timestamps, required addresses, and relevant payload details appear before archiving or deleting the source.

PCAPNG vs TXT: format comparison

How the PCAPNG and TXT formats compare on the properties that matter most for this conversion.

Comparison of the PCAPNG and TXT file formats
Property .PCAPNG PCAP Next Generation Capture File Format .TXT Plain Text File
Open standard Yes Yes
Compression Uncompressed Uncompressed
Typical file size Large Very small
Opens in a web browser No Yes, natively
Further editing Not directly editable Easy
Metadata support Extensive None
Plain-text readable No Yes
Best used for Data exchange Data exchange
Introduced 2008 —
Developer IETF (working group; widely used in Wireshark/libpcap ecosystem) —
MIME type application/octet-stream text/plain

Additional formats for
pcapng file conversion

Convert to txt from
other formats

Share on social media: