Wireshark mailing list archives
Tshark Tcap filtering
From: Erdinç Taşkın <erdinctaskin () gmail com>
Date: Tue, 20 Sep 2011 15:32:18 +0300
Hello, I have a problem about filtering from pcap file. I got a capture file that created by tcpdump. I use filter criteria that "(tcap.tid == 01:5e:00:00) || (tcap.tid == 53:d0:90:96)" on wireshark found packet. On same capture file, using tshark (exact command "/tshark -R "(tcap.tid == 01:5e:00:00) || (tcap.tid == 53:d0:90:96)" -r test.pcap") does not match any packet. What is wrong? Thanks for helps
___________________________________________________________________________ Sent via: Wireshark-users mailing list <wireshark-users () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-users Unsubscribe: https://wireshark.org/mailman/options/wireshark-users mailto:wireshark-users-request () wireshark org?subject=unsubscribe
Current thread:
- Tshark Tcap filtering Erdinç Taşkın (Sep 20)
- Re: Tshark Tcap filtering Jeff Morriss (Sep 20)
- merged capture file filtering Malcolm Herbert (Sep 20)
- Re: merged capture file filtering Malcolm Herbert (Sep 21)
- Re: Tshark Tcap filtering Erdinç Taşkın (Sep 23)
- merged capture file filtering Malcolm Herbert (Sep 20)
- Re: Tshark Tcap filtering Jeff Morriss (Sep 20)