Wireshark mailing list archives
For TShark, provide a way to control the output format. E.g., 'tshark -e "ip udp tcp.port"' would expand the IP and UDP sections, and display the TCP port information.
From: Yee Man Bergstrom <yee.man.bergstrom () gmail com>
Date: Tue, 13 Sep 2011 18:05:25 -0500
Hi,
From http://wiki.wireshark.org/WishList
For TShark, provide a way to control the output format. E.g., 'tshark -e "ip udp tcp.port"' would expand the IP and UDP sections, and display the TCP port information. This is already done in trunk as of revision 38990 unless I am missing something. You can perform the above scenario with Ø tshark T fields e ip e udp e tcp.port Can someone familiar with when this was done update the wiki page http://wiki.wireshark.org/WishList? Thanks! YeeMan
___________________________________________________________________________ Sent via: Wireshark-dev mailing list <wireshark-dev () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev mailto:wireshark-dev-request () wireshark org?subject=unsubscribe
Current thread:
- For TShark, provide a way to control the output format. E.g., 'tshark -e "ip udp tcp.port"' would expand the IP and UDP sections, and display the TCP port information. Yee Man Bergstrom (Sep 13)
- Re: For TShark, provide a way to control the output format. E.g., 'tshark -e "ip udp tcp.port"' would expand the IP and UDP sections and display the TCP port information. Chris Maynard (Sep 14)
- Re: For TShark, provide a way to control the output format. E.g., 'tshark -e "ip udp tcp.port"' would expand the IP and UDP sections, and display the TCP port information. Guy Harris (Sep 14)