Wireshark mailing list archives
Re: tshark conversatons
From: "j.snelders" <j.snelders () telfort nl>
Date: Fri, 26 Feb 2010 17:37:52 +0100
Hi,
You can use the option -q (be more quiet on stout):
$ tshark -r test.pcap -q -z conv,tcp,tcp.port==80
================================================================================
TCP Conversations
Filter:tcp.port==80
| <- | |
-> | | Total |
| Frames Bytes | | Frames
Bytes | | Frames Bytes |
192.168.1.4:49380 <-> 62.69.179.205:80 49 57496 34
5023 83 62519
192.168.1.4:49376 <-> 62.69.179.205:80 50 58468 33
4981 83 63449
192.168.1.4:49401 <-> 194.17.45.181:80 49 69352 27
3992 76 73344
192.168.1.4:49404 <-> 8.12.214.126:80 34 46257 19
2292 53 48549
Best regards
Joan
On: Fri, 26 Feb 2010 15:11:14 +0100 fajfusio wrote:
Hello How can I print the list of conversations contained in a file. E.g. I want to see conversations on a specific server port. I try something like:
tshark
-z conv,tcp,"tcp.port==139" -r file.pcap Unfortunately it just prints the contents of a file. thank you for help
___________________________________________________________________________
Sent via: Wireshark-users mailing list <wireshark-users () wireshark org>
Archives: http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
mailto:wireshark-users-request () wireshark org?subject=unsubscribe
Current thread:
- tshark conversatons fajfusio (Feb 26)
- Re: tshark conversatons j.snelders (Feb 26)
