Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] Parse fields from packets

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: Stephen Fisher <stephentfisher@xxxxxxxxx>
Date: Fri, 6 Jul 2007 21:07:23 -0700

On Fri, Jul 06, 2007 at 10:36:30PM -0500, Jason Bush wrote:

> This new feature has of course brought on another question. I am
> particularly interested in using the '-E separator' option... is there
> a way to use this and have multiple characters separate the fields
> (rather than one)?

I just checked the code - it is limited to a single character.  Although
there are some special sequences you can pass to the -E option: /t for a
tab, /s for a space, and / by itself or with any other character (such
as /z) for '\'.


Steve


  • References:
    • Re: [Wireshark-users] Parse fields from packets
      • From: Jason Bush
  • Prev by Date: Re: [Wireshark-users] Parse fields from packets
  • Next by Date: Re: [Wireshark-users] Parse fields from packets
  • Previous by thread: Re: [Wireshark-users] Parse fields from packets
  • Next by thread: Re: [Wireshark-users] Parse fields from packets
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation