stats_by_proto
Protocol hierarchy statistics
How to use it
stats_by_proto is exposed by the MCP Wireshark MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the stats_by_proto tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.
Install MCP Wireshark
claude mcp add --transport stdio --scope user mcp-wireshark -- mcp-wiresharkOther tools in MCP Wireshark (13)
Health triage for GOOSE/SV/MMS captures: per-source OK/WARN/FAIL with sqNum/stNum gaps, TTL violations, smpCnt discontinuities, lost sync, and MMS errors
Verify tshark is installed and show version
Extract protocol fields as a TSV table. Curated defaults for HTTP, DNS, TLS, GOOSE, MMS, SV, SIP, ICMP; arbitrary fields for any other protocol
Apply a Wireshark display filter to a pcap
tshark expert analysis: warnings, errors, and notes grouped by severity
Export packets from a pcap to a JSON file at a path you choose
Reassemble a TCP stream and return its payload
Reassemble a UDP stream and return its payload
List network interfaces available to capture from
Capture live traffic from an interface (capped at 5 minutes / 10k packets)
Aggregate -z reports (protocol hierarchy, conversations, endpoints, HTTP/DNS/SMB stats)
Read packets from a .pcap / .pcapng file (preview + total count)
High-level summary: I/O stats, protocol hierarchy, top talkers