From: "Jaap Keuter" <jaap.keuter@xxxxxxxxx>
| On 06/23/2010 11:00 PM, David H. Lipman wrote:
>> The server admin provided the following to me Today...
>> "I record pcap with tshark, so what I need is a tshark capture filter."
| Hi,
| Well then, tell him to add:
| -f "not udp port 137" to the tshark command line.
Command Line switches are not a god idea as this is only the beginning of filtering out
process.
Does TShark interpret a disk file with these directives ?
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp