Wireshark mailing list archives

Re: Output of 'tshark -T fields' with multipleoccurrences of a field


From: "Boonie" <newsboonie () gmail com>
Date: Thu, 15 Jul 2010 20:29:18 +0200


----- Original Message ----- 
From: "Sake Blok" <sake () euronet nl>
To: "Community support list for Wireshark" <wireshark-users () wireshark org>; 
"Developer support list for Wireshark" <wireshark-dev () wireshark org>
Sent: Wednesday, July 14, 2010 10:43 PM
Subject: [Wireshark-users] Output of 'tshark -T fields' with 
multipleoccurrences of a field


Hi,

Recently a lot of questions have been asked on this list (and also at 
Sharkfest) about the output of 'tshark -T fields -e <field>' when <field> 
had multiple occurrences in one packet. Only the last occurrence was 
printed by tshark. I submitted a fix that now prints all occurrences, 
aggregated by commas (which can be overwritten with -E aggregator=<char>).

The fix will be included in version 1.6.x as well as in the next 
development release (1.5.x). For the impatient, please use an automated 
build from http://www.wireshark.org/download/automated/ (look for a 
version 33504 or higher).

Thanks a lot Sake. That is helpfull. I've tested and it works nicely for me.

Unfortunately the latest build keeps crashing the main wireshark tool.

Dave 

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: