Home page logo

wireshark logo Wireshark mailing list archives

Re: newbie question, tshark input from stdin
From: Christopher Maynard <Christopher.Maynard () gtech com>
Date: Fri, 7 Feb 2014 22:37:51 +0000 (UTC)

Jaap Keuter <jaap.keuter ()    > writes:

That's probably because -r refers to a file (which you can seek through),
-i refers to a 'stream' (which you cannot seek). Now, tcpdump is single pass
while *shark has multi pass capability *for files*. Categorizing pipes in
as files would open up that multi pass option, which it cannot handle, while
tcpdump would never do that so it can access a pipe as a file.

What about allowing "-r -", but just treating it exactly the same as if "-i
-" had been specified?

Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]