https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3818
Summary: Bug when selecting fields in TShark
Product: Wireshark
Version: 1.2.0
Platform: All
OS/Version: All
Status: NEW
Severity: Normal
Priority: Low
Component: TShark
AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
ReportedBy: joan@xxxxxxxxx
Created an attachment (id=3468)
--> (https://bugs.wireshark.org/bugzilla/attachment.cgi?id=3468)
Example_pcap
Build Information:
TShark 1.2.0 (SVN Rev 25444)
Copyright 1998-2009 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
Compiled with GLib 2.16.2, with libpcap 0.9.8, with libz 1.2.3, without POSIX
capabilities, with libpcre 7.6, with SMI 0.4.5, without c-ares, with ADNS,
without Lua, without GnuTLS, without Gcrypt, without Kerberos, without GeoIP.
Running on Linux 2.6.24.7-laptop-2mnb, with libpcap version 0.9.8.
Built using gcc 4.2.3 (4.2.3-6mnb1).
--
When you pass fields to TShark, for example:
tshark -Tfields -e frame.number -e 104apci -e 104asdu -r
e:\bug_tshark_dissects_last_field.pcap
tshark only dissects the last occurrence of the fields.
See the attached example. In this case, the field 104asdu appears 4 times and
its only dissected the last one.
--
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.