Wireshark-users: Re: [Wireshark-users] tshark -T fields and info column
: "Elvis" <wireshark@xxxxxxxxxxxx
: Mon, 26 May 2008 17:52:18 -0700 (PDT)
> It works pretty well for me, except I'd like it to have a specific
> delimiter for parsing. This is one place Tshark needs a little
> tweaking, something I might look into later.
In total agreement. I dug around a bit to see if it such an option already
exists. It doesn't. The formatting code is in tshark.c print_columns(). I
think a new command line switch would be required for this, which is
probably not the most politically simple thing to do....
I also thought it would be nice to know where all the % options are
defined, but couldn't find anything over Sunday morning coffee :)