Documentation
Redirect and export
Three ways to get data out, for three different jobs.
1. Export the visible view
Save the current view as a file. These are the formats you can choose from, and the numbering follows the order in the file dialog.
- ANSI text
- Plain text, no byte-order mark, no header.
- Unicode text
- UTF-16LE with a byte-order mark.
- HTML
- A self-contained page with the same row classes as the view.
- CSV
- UTF-8 with a byte-order mark, header row, RFC 4180 quoting.
The exported columns are the ones on screen, so with a masked licence the protocol column exports as **** like everything else.
Rows are written lazily, one at a time, so exporting from a very large capture does not build the whole file in memory first. Exporting needs a licence: a trial key caps a snapshot export at 500 rows, and a full licence removes that cap.
2. Export the whole frame pool
The frame pool is every frame that was captured, whatever the row filter is hiding and whatever columns you switched off. This is the one export reserved for Professional; the visible-view export above comes with Standard.
- JSON Lines: one compact JSON object per frame, fields in a fixed order, no byte-order mark.
- PCAP: little-endian, link type 147, so Wireshark shows the raw frame bytes rather than a protocol it guessed.
Default file names are the session name plus the view name in English - COM7_Table.csv, COM7_Line.json, COM7_Table.pcap - so the same capture is easy to find again.
3. Redirect while capturing
Redirect appends the new rows of the active view to a file as they arrive. The file is flushed every five seconds or as soon as the buffer reaches 256 KB, so a crash costs you seconds, not the session.
- Single file
- One file, appended until you stop.
- By time
- A new file every N hours, minutes or seconds.
- By size
- A new file every N kilobytes or megabytes.
- Overwrite by size
- Reuse one file, overwriting it when the size is reached.
- Split files are named with a timestamp suffix, and a name collision is resolved with a numeric suffix instead of truncating.
- A single file stops at 1 GB and reports it in the Problems panel.
- The row filter is applied to redirect as well, so what you see is what gets written.
4. Forward to TCP or HTTP
Forwarding sends captured frames to another process, on your own network.
- Batches of up to 100 frames, each batch prefixed with its length as a 4-byte big-endian integer, followed by a UTF-8 JSON array.
- TCP is the primary channel; the HTTP path posts the same batch to /batch and is used as the fallback.
- The destination host, transport, ports and enable flag are all configured in Settings, and the forwarder counts what it sent, retried and dropped.
- Without protocol analysis the frame data in a batch is replaced by **** - the hex, str and parse fields. Frames are not dropped: timestamps, direction, port and length are sent as usual.

