Dump WebSocket traffic From pcap file: $ tshark -Tfields -Y websocket.payload -E occurrence=l -e tcp.srcport -e text -r websocket.pcap Capture: $ tshark -Tfields -Y websocket.payload -E occurrence=l -e tcp.srcport -e text -i lo port 12345