Wireshark-users: [Wireshark-users] tshark commands
: David Milbourne <dmilbo@xxxxxxxxx
: Wed, 19 May 2010 12:49:20 -0400
I'm trying to figure out how to use Wireshark's "Follow TCP Stream" feature in tshark. For example, I have a PCAP file and I'd like to extract out all of the .ntf files. I know if I type:
tshark -r server.pcap -R "data contains NTF0"
This will show me a list of the streams in the PCAP file that contain the above string. However, how can I re-create these files (similar to "Follow TCP Stream" and "save as" in Wireshark)?