Wireshark-users: [Wireshark-users] Follow tcp stream possible when using -z io stats option in t-

From: "Felix Faassen" <Felix.Faassen@xxxxxxxxxx>
Date: Thu, 25 Jan 2007 11:26:19 +0100
Hi,
 
I've a question concerning t-shark. I'm running script which measures HTTP GET requests. However I also would like to include the HTTP response back from the server. I use the -z io,stats option in order to get IO statistics which I parse into an excel document.
 
eg: I've got a filter defined as follows.
 
(this is unique for my capture)
ip.addr==10.0.0.1 && http.request.uri contains felix
 
This captures all my request to the server. Now I want to be able to also include all the TCP packages which belong to the packet which adheres to my capture condition.
 
 In Wireshark you have the option to click on a TCP packet and select "follow tcp stream".
 Is there a way in which I can get Tshark to both count the HTTP request and its corresponding tcp packets response in T-shark when using the -z io,stats option?
 
 
Thanks so much.
 
Cheers,
 
Felix Faassen


This e-mail message contains information which is confidential and may be privileged. It is intended for use by the addressee only. If you are not the intended addressee, we request that you notify the sender immediately and delete or destroy this e-mail message and any attachment(s), without copying, saving, forwarding, disclosing or using its contents in any other way. TomTom N.V., TomTom International BV or any other company belonging to the TomTom group of companies will not be liable for damage relating to the communication by e-mail of data, documents or any other information.