mailing list archives
Re: newbie question, tshark input from stdin
From: Christopher Maynard <Christopher.Maynard () gtech com>
Date: Fri, 7 Feb 2014 22:37:51 +0000 (UTC)
Jaap Keuter <jaap.keuter () > writes:
That's probably because -r refers to a file (which you can seek through),
-i refers to a 'stream' (which you cannot seek). Now, tcpdump is single pass
while *shark has multi pass capability *for files*. Categorizing pipes in
as files would open up that multi pass option, which it cannot handle, while
tcpdump would never do that so it can access a pipe as a file.
What about allowing "-r -", but just treating it exactly the same as if "-i
-" had been specified?
Sent via: Wireshark-users mailing list <wireshark-users () wireshark org>
mailto:wireshark-users-request () wireshark org?subject=unsubscribe