follow_udp
Reassemble a UDP stream and return its payload
How to use it
Project documentation lists follow_udp for the MCP Wireshark MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), then check which tools your installed version makes available. Tool availability can depend on configuration and credentials. A server handshake does not verify this tool’s behavior. See the full listing for setup details.
Install MCP Wireshark
claude mcp add --transport stdio --scope user mcp-wireshark -- mcp-wiresharkOther tools in MCP Wireshark (13)
Health triage for GOOSE/SV/MMS captures: per-source OK/WARN/FAIL with sqNum/stNum gaps, TTL violations, smpCnt discontinuities, lost sync, and MMS errors
Verify tshark is installed and show version
Extract protocol fields as a TSV table. Curated defaults for HTTP, DNS, TLS, GOOSE, MMS, SV, SIP, ICMP; arbitrary fields for any other protocol
Apply a Wireshark display filter to a pcap
tshark expert analysis: warnings, errors, and notes grouped by severity
Export packets from a pcap to a JSON file at a path you choose
Reassemble a TCP stream and return its payload
List network interfaces available to capture from
Capture live traffic from an interface (capped at 5 minutes / 10k packets)
Aggregate -z reports (protocol hierarchy, conversations, endpoints, HTTP/DNS/SMB stats)
Read packets from a .pcap / .pcapng file (preview + total count)
Protocol hierarchy statistics
High-level summary: I/O stats, protocol hierarchy, top talkers