Wireshark-users: Re: [Wireshark-users] Reading tshark output using wireshark

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Mon, 30 Apr 2007 01:52:24 -0700
Philipp Walther wrote:

[root@chgfssonictest01 ~]# tshark -w sniff.txt -s 65535 -c 1000 -l

The output of tshark, with the "-w" flag, isn't text, so you should probably pick a different suffix such as ".pcap". (I don't know whether scp was being "clever" and translating LF on UN*X to CR/LF on Windows, as per Sake Blok's comment and your response, but, if it was, perhaps calling the file "sniff.pcap" would avoid that. It'd also probably avoid Windows starting up Notepad or Wordpad or whatever on the file when you try to open it - *that* wouldn't work very well.)