Wireshark mailing list archives

Re: Tshark - displaying all sdp.media_attr on win2k system


From: "Boonie" <newsboonie () gmail com>
Date: Tue, 9 Nov 2010 19:38:03 +0100



You might be able to use something like: tshark -R "frame contains FOO"
or even: tshark -R "sdp.media_attr && frame contains FOO"

I'll try just that. I don't need the actual contents. I just need the source 
IP. I hope this works.

Remote capture is not an option. I only have remote desktop and SFTP access. 
And I have some 4000 files of 50MB. This is about one day worth of data. The 
next day, we'll have the same load.

Thanks a lot,

Dave 

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe


Current thread: