Wireshark mailing list archives

Re: how to show protocol with tshark


From: nangergong <nangergong () gmail com>
Date: Tue, 5 Jun 2012 18:47:35 +0200

yes, thanks

On Tue, Jun 5, 2012 at 4:00 PM, Jeff Morriss <jeff.morriss.ws () gmail com>wrote:

nangergong wrote:

HI, all:

    In wireshark, I can see protocol names such as "TCP","UDP","DHCPV6",
"LLMNR", is it possible to use tshark to show these protocol names,
especially with "-e", thanks!


Does this do what you want?

tshark -T fields -eframes.protocols -nr /path/to/file.pcap
______________________________**______________________________**
_______________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org**

Archives:    http://www.wireshark.org/**lists/wireshark-users<http://www.wireshark.org/lists/wireshark-users>
Unsubscribe: 
https://wireshark.org/mailman/**options/wireshark-users<https://wireshark.org/mailman/options/wireshark-users>
           mailto:wireshark-users-**request () wireshark org<wireshark-users-request () wireshark org>
?subject=**unsubscribe

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

Current thread: