Ethereal-users: Re: [Ethereal-users] Tethereal filtering - file to file

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: "M.C. van den Bovenkamp" <marco@xxxxxxxxxxxxxxxxxxx>
Date: Wed, 21 Nov 2001 14:20:15 +0100
Tinga Shilo wrote:


- What filters should I use, capture-filters or read-filters ?


Depends on what you want to do. If you can filter on it with a pcap-style filter, you can use a capture filter ('-f' or command line arguments), if not, you have to use a display filter ('-R' option).


- The "-c" option works, but can I do something like "the last 100 packets of the file" ?


Editcap can do that.


- Can I do something like "all the packets between two time stamps in the file" ?


With tethereal and a display filter on 'frame.time' you should be able to.

			Regards,

				Marco.