Thanks Abhijit, a few issues with this thread, most important being I am using Windows which rules out tcpflow and any other *nix based tool. Also, I am not searching for any particular string and I need output(printed or saved ) exactly like "Follow TCP Stream->Save As" in Wireshark. I am trying to convince myself that there is an option in tshark since the bevaior is defined in Wireshark... but I am having a hard time believing there is hardly anyone out there in search of similar functionality.
AG
From: Abhijit Bare
<abhibare@xxxxxxxxx>
To: Community support list for Wireshark <wireshark-users@xxxxxxxxxxxxx>
Sent: Mon, December 27, 2010 5:51:03 PM
Subject: Re: [Wireshark-users] tshark Question
Wondering if this thread will help you...