Wireshark mailing list archives
Re: tshark conversatons
From: "j.snelders" <j.snelders () telfort nl>
Date: Fri, 26 Feb 2010 17:37:52 +0100
Hi, You can use the option -q (be more quiet on stout): $ tshark -r test.pcap -q -z conv,tcp,tcp.port==80 ================================================================================ TCP Conversations Filter:tcp.port==80 | <- | | -> | | Total | | Frames Bytes | | Frames Bytes | | Frames Bytes | 192.168.1.4:49380 <-> 62.69.179.205:80 49 57496 34 5023 83 62519 192.168.1.4:49376 <-> 62.69.179.205:80 50 58468 33 4981 83 63449 192.168.1.4:49401 <-> 194.17.45.181:80 49 69352 27 3992 76 73344 192.168.1.4:49404 <-> 8.12.214.126:80 34 46257 19 2292 53 48549 Best regards Joan On: Fri, 26 Feb 2010 15:11:14 +0100 fajfusio wrote:
Hello How can I print the list of conversations contained in a file. E.g. I want to see conversations on a specific server port. I try something like:
tshark
-z conv,tcp,"tcp.port==139" -r file.pcap Unfortunately it just prints the contents of a file. thank you for help
___________________________________________________________________________ Sent via: Wireshark-users mailing list <wireshark-users () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-users Unsubscribe: https://wireshark.org/mailman/options/wireshark-users mailto:wireshark-users-request () wireshark org?subject=unsubscribe
Current thread:
- tshark conversatons fajfusio (Feb 26)
- Re: tshark conversatons j.snelders (Feb 26)