On Thu, Jul 9, 2009 at 2:01 AM, Abhik Sarkar
<sarkar.abhik@xxxxxxxxx> wrote:
I am attempting to create a display filter but some how keep missing the mark. I would like to create a filter that would read:
Beginning byte= 0038
Length= 4
Data="" 74:72:61:70
Something like this:
frame[0x38:4]==74:72:61:70
Is it possible to use this same approach in tshark with -T fields?
that is to say, something like:
tshark -r infile.cap -T fields -e frame[0x38:4]
I tried this and it didn't work, but hoping maybe my syntax needs adjusting.
--
-jp
If your friend is already dead, and being eaten by vultures, I think it's okay
to feed some bits of your friend to one of the vultures, to teach him to do
some tricks. But ONLY if you're serious about adopting the vulture.
deepthoughtsbyjackhandey.com