Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-dev: Re: [Ethereal-dev] TCP sniffing using Tethereal

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Ulf Lamping <ulf.lamping@xxxxxx>
Date: Thu, 16 Sep 2004 19:22:18 +0200
Gilad Evrony wrote:

I think it would be a very powerful tool to be able to use ethereal's read filters to sniff whole TCP/UDP sessions.

What do you mean with a read filter? A capture or a display filter?

That way, when a packet matches my filter, not only is it saved to disk but also the whole TCP/UDP session it belongs to.

Do you mean to save all session into different files while capturing?

Also, it would be nice if the etheral could create all the TCP/UDP streams in a file, rather than having to click one by one (Iris
does this pretty well).

Create streams in a file?

If anyone knows how to do this or can advise me how I'd appreciate it.

Please give a little more details of your thoughts, your descriptions are very short.

Regards, ULFL