Wireshark-users: Re: [Wireshark-users] Filter existing file

From: Stephen Fisher <stephentfisher@xxxxxxxxx>
Date: Tue, 22 Jan 2008 09:10:57 -0700
On Tue, Jan 22, 2008 at 04:39:19PM +0100, Kuhs Lukas wrote:

> I want to filter an existing pcap-file using dumpcap on Windows. This 
> is not possible since there is no infile option anymore. Tethereal had 
> this option. My question is, whether this will be included in a later 
> version or not. Do you know any workaround except for using tethereal? 
> I need to execute it on the command line.

Have you tried using tshark?  It is the new version of tethereal.


Steve