Wireshark mailing list archives

Tshark Tcap filtering


From: Erdinç Taşkın <erdinctaskin () gmail com>
Date: Tue, 20 Sep 2011 15:32:18 +0300

Hello,

I have a problem about filtering from pcap file. I got a capture file that
created by tcpdump. I use filter criteria that "(tcap.tid == 01:5e:00:00) ||
(tcap.tid == 53:d0:90:96)" on wireshark found packet. On same capture file,
using tshark (exact command "/tshark -R "(tcap.tid == 01:5e:00:00) ||
(tcap.tid == 53:d0:90:96)" -r test.pcap") does not match any packet. What is
wrong?

Thanks for helps
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

Current thread: