On Sep 10, 2015, at 1:05 PM, Pascal Quantin <pascal.quantin@xxxxxxxxx> wrote:
> Just a random thought (as I'm far from being a script expert). In case only one of the 2 IP address is resolved, would it be harder to parse?
> Src:, Dst: localhost (
Is it harder to parse that or
(PSML) or,
(-T fields -E separator=, -e _ws.col.Source -e _ws.col.Destination)?
Perhaps the default packet detail output should be oriented towards being read by humans, with the output of -T psml, -T ldml, and -T fields being what you use if you want it to be read by software?