Wireshark-users: Re: [Wireshark-users] Question

From: "Terry Martin" <tmartin@xxxxxxxxxxxxxxxx>
Date: Thu, 13 Nov 2008 13:38:57 -0500
thanks

Terry Martin
TimeData Corporation
VP of Network Operation
East Coast Number:     212-644-1600 X3
West Coast Number     503-678-2224
Cell:                            503-318-8909
 

-----Original Message-----
From: wireshark-users-bounces@xxxxxxxxxxxxx
[mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Sake Blok
Sent: Thursday, November 13, 2008 10:29 AM
To: Community support list for Wireshark
Subject: Re: [Wireshark-users] Question

On Thu, Nov 13, 2008 at 01:13:58PM -0500, Terry Martin wrote:
> 
> I just reviewed the packet and I am going to need the IGMP information
> which is the next 64 bytes.  
> 
> Is this going to be difficult? Should I collect the entire packet?

Nope, just change the value of the -s <X> option to suit your need. It
just
cuts off the packet after X bytes. You might want to tune the parameter
so that is fits your need.

> If so is Dumpcap still the best?

Yes.

Cheers,
   Sake
_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
https://wireshark.org/mailman/listinfo/wireshark-users