Skip to main content

Capturing DTMF using Wireshark

Scope

Intended Audience: T1 Technician, WLPs

This article goes over how to capture DTMF using a Wireshark PCAP

Requirements

  • Access to Wireshark

  1. Open the Wireshark PCAP
  2. Filter on SIP packets
  3. Select Telephony > VoIP Calls from the Menu Bar A screenshot of a computer Description automatically generated
  4. Select your call and click Flow Sequence at the bottom of the screen A screenshot of a computer Description automatically generated
  5. This graphic will display the DTMF as RTP events. A screenshot of a computer Description automatically generated

Alternate Method

  • Filter for rtpevent A screenshot of a computer Description automatically generated
    • This method is not as clean as the previous method, but provides more detailed information.
    • The DTMF key is not ended until you see the (end) event. (see the RED and GREEN highlights in the image above
    • Clicking on a single line will provide additional information at the bottom of the wireshark app.