Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
WIRESHARK_MCP_TRANSPORTNoTransport protocol for the MCP server (stdio, sse, etc.).stdio
WIRESHARK_MCP_DFTEST_PATHNoAbsolute path to the dftest binary.
WIRESHARK_MCP_TSHARK_PATHNoAbsolute path to the tshark binary.
WIRESHARK_MCP_DUMPCAP_PATHNoAbsolute path to the dumpcap binary.
WIRESHARK_MCP_ALLOWED_ROOTSYesAbsolute path(s) to directories the server is allowed to read/write. Must be a JSON array of strings.
WIRESHARK_MCP_RAWSHARK_PATHNoAbsolute path to the rawshark binary.
WIRESHARK_MCP_WIRESHARK_PATHNoAbsolute path to the Wireshark binary.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
ws_runtime_infoA

Get Wireshark runtime information: installed binaries, versions, available features, and allowed file roots.

capture_list_interfacesA

List available network interfaces for packet capture. Returns interface names, display names, and addresses.

capture_get_interface_capabilitiesA

Get detailed capabilities of a specific network interface, including supported link types and timestamp types.

filter_validate_displayA

Validate a Wireshark display filter expression. Returns whether the filter syntax is valid. Does not require an active analysis session.

filter_validate_captureA

Validate a BPF capture filter expression for a specific interface. The interface is required because filter compilation depends on the link type.

filter_completeA

Auto-complete display filter field names. Requires an active analysis session (sharkd command).

field_listA

List available protocol fields, optionally filtered by prefix. Supports pagination. Uses tshark -G fields (no session required).

field_getA

Get detailed information about a specific protocol field by its abbreviation (e.g., 'ip.src', 'tcp.port'). Use the 'id' value from field_list results. Requires an active analysis session.

capture_startA

Start live packet capture on a network interface. Requires root or cap_net_raw capability. Returns a session ID for tracking.

capture_stopA

Stop a running packet capture. Idempotent - safe to call multiple times.

capture_statusA

Get the current status of a capture session, including packet counts and file information.

capture_list_sessionsB

List all capture sessions, optionally filtered by status.

capture_list_filesA

List files produced by a capture session. In ring buffer mode, multiple files may exist.

capture_read_logB

Read the capture session log (dumpcap stderr output).

analysis_openA

Open a capture file for analysis using sharkd. Either provide file_path directly or capture_session_id to select from capture output. Returns session ID and file summary.

analysis_closeA

Close an analysis session and release resources.

analysis_statusA

Get the current status of an analysis session including frame count and duration.

analysis_summaryA

Get a comprehensive summary of the loaded capture file including frame count, duration, protocols, and time range.

analysis_list_sessionsA

List all analysis sessions, optionally filtered by status (ready, closed, failed).

analysis_catalogA

Get the capability catalog of an analysis session: available taps, follow protocols, statistics, columns, and encapsulation types. Use this to discover what analysis operations are available.

analysis_list_framesB

List frame summaries with optional display filter and pagination. Returns frame numbers, column values, and metadata flags.

analysis_get_frameB

Get the complete protocol dissection tree for a single frame. Returns protocol layers, field values, and optionally raw bytes.

analysis_get_statisticsB

Execute a sharkd tap for statistical analysis. Returns table, tree, or graph results depending on the tap type. Use analysis_catalog to discover available taps. Friendly selector shorthands such as 'conv,tcp' are accepted.

analysis_follow_streamA

Reassemble and follow a protocol stream (TCP, UDP, TLS, HTTP, etc.). Use analysis_get_frame's follow_filters to get the protocol and filter values.

analysis_iographB

Generate I/O graph time-series data. Specify up to 10 graph definitions with metrics and optional filters.

analysis_intervalsA

Get frame count and byte statistics per time interval. Useful for traffic pattern analysis.

analysis_list_tcp_conversationsA

List TCP conversations without requiring manual sharkd tap syntax.

analysis_list_tls_sniB

List TLS Server Name Indication values grouped by hostname.

analysis_list_http_hostsA

List HTTP hosts grouped by request host with example methods and URIs.

analysis_download_artifactB

Download an exported object, RTP stream audio, or TLS key log from sharkd. Tokens come from analysis_get_statistics (export_objects, rtp_streams) or fixed tokens like 'ssl-secrets'.

file_capinfosA

Get capture file metadata including packet count, duration, file type, and optionally file hashes.

file_detect_typeB

Identify the format of a capture file (pcap, pcapng, etc.).

file_mergeA

Merge two or more capture files into one. 'merge' interleaves by timestamp, 'concat' appends sequentially.

file_sliceB

Extract packets from a capture file by packet number ranges or time window.

file_dedupC

Remove duplicate packets from a capture file.

file_retimeC

Adjust packet timestamps in a capture file.

file_write_filtered_captureA

Filter packets by display filter and write matching frames to a new capture file. Unlike file_slice (packet ranges), this filters by protocol content.

file_tshark_exportA

Export packet data in structured format (fields, json, or ek). For writing filtered pcap files, use file_write_filtered_capture instead.

Prompts

Interactive templates invoked by user choice

NameDescription
analyze_captureStep-by-step guide to comprehensively analyze a capture file.
investigate_connectionDeep investigation of a specific network connection.
dns_analysisAnalyze DNS traffic patterns in a capture.
http_analysisAnalyze HTTP request/response traffic.
security_auditSecurity-focused analysis of network traffic.
compare_capturesCompare two capture files.

Resources

Contextual data attached and managed by the client

NameDescription
interfaces_resourceAvailable network interfaces.
version_resourceWireshark version information.

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Pupillen/wireshark-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server