Wireshark mailing list archives
tshark -x options
From: kahou lei <kahou82 () gmail com>
Date: Tue, 13 Mar 2012 14:45:17 -0700
Hi, I am trying to display the hex value of the packet. Currently I am using "-x" option in tshark and I get this output: 1 62 0.000000 212.179.66.74 -> 224.0.0.2 HSRP Hello (state Active) 62 0000 01 00 5e 00 00 02 00 00 0c 07 ac 01 08 00 45 c0 ..^...........E. 0010 00 30 00 00 00 00 02 11 c0 fd d4 b3 42 4a e0 00 .0..........BJ.. 0020 00 02 07 c1 07 c1 00 1c 81 00 00 00 10 03 0a 69 ...............i 0030 01 00 63 69 73 63 6f 00 00 00 d4 b3 42 46 ..cisco.....BF But when I use wireshark "Export" function with only packet byte enabled, I don't get the description of the packet. That is, I only get this: 0000 01 00 5e 00 00 02 00 00 0c 07 ac 01 08 00 45 c0 ..^...........E. 0010 00 30 00 00 00 00 02 11 c0 fd d4 b3 42 4a e0 00 .0..........BJ.. 0020 00 02 07 c1 07 c1 00 1c 81 00 00 00 10 03 0a 69 ...............i 0030 01 00 63 69 73 63 6f 00 00 00 d4 b3 42 46 ..cisco.....BF Can anyone tell me if I can achieve the same thing that wireshark does in tshark? Thanks, Kahou
___________________________________________________________________________ Sent via: Wireshark-dev mailing list <wireshark-dev () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev mailto:wireshark-dev-request () wireshark org?subject=unsubscribe
Current thread:
- tshark -x options kahou lei (Mar 13)
- Re: tshark -x options Guy Harris (Mar 13)
- Re: tshark -x options Jeff Morriss (Mar 13)
- Re: tshark -x options Guy Harris (Mar 13)
- Re: tshark -x options Jeff Morriss (Mar 14)
- Re: tshark -x options Jeff Morriss (Mar 13)
- Re: tshark -x options Guy Harris (Mar 13)
- <Possible follow-ups>
- Re: tshark -x options kahou lei (Mar 14)
- Re: tshark -x options Guy Harris (Mar 14)