--- Comment #2 from Steve Crye <stcrye@xxxxxxxxx> 2011-06-01 09:54:02 PDT ---
Here is an example of the tshark command I'm using. I've tried it with various
different filesize and files settings.

tshark  -f"ip proto 0x2f" -b filesize:20000 -b files:4 -w ringbuff\scanit.pcap



