Wireshark-users: Re: [Wireshark-users] Print wireshark option from command

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Tue, 16 Dec 2008 00:46:09 -0800

On Dec 16, 2008, at 12:37 AM, Stephen Fisher wrote:

You need to use -Tfields instead of -Ttext

Is there a way to get the value of the protocol column with "-T fields" and "-e"? Everything else is a field (although he might want the generic source and destination addresses if he has any non-IPv4 traffic), but the column values aren't necessarily registered fields.