ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-bugs: [Wireshark-bugs] [Bug 6131] New: Tshark custom columns: Why don't I get an error

Date: Sat, 16 Jul 2011 07:46:37 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6131

           Summary: Tshark custom columns: Why don't I get an error
                    message?
           Product: Wireshark
           Version: 1.4.0
          Platform: x86
        OS/Version: Windows XP
            Status: NEW
          Severity: Minor
          Priority: Low
         Component: TShark
        AssignedTo: bugzilla-admin@xxxxxxxxxxxxx
        ReportedBy: j.snelders@xxxxxxxxxx


Build Information:
$ tshark -v
TShark 1.6.0rc1 (SVN Rev 37186 from /trunk-1.6)

Copyright 1998-2011 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled (32-bit) with GLib 2.26.1, with WinPcap (version unknown), with libz
1.2.5, without POSIX capabilities, without libpcre, with SMI 0.4.8, with c-ares
1.7.1, with Lua 5.1, without Python, with GnuTLS 2.10.3, with Gcrypt 1.4.6,
with

MIT Kerberos, with GeoIP.

Running on Windows XP Service Pack 3, build 2600, with WinPcap version 4.1.2
(packet.dll version 4.1.0.2001), based on libpcap version 1.0 branch 1_0_rel0b
(20091008).

Built using Microsoft Visual C++ 9.0 build 21022
--
Correct syntax:
$ tshark -r test.pcap -R "frame.number<6" -o column.format:""No.","%m",
"tcp.port", "%Cus:tcp.port", "udp.port", "%Cus:udp.port""
  1  55556,53
  2  53,55556
  3 1685,80
  4 80,1685
  5 1685,80

I get an error message, when I make a typo: %Cu:udp.port (instead of
%Cus:udp.port)
$ tshark -r test.pcap -R "frame.number<6" -o column.format:""No.","%m",
"tcp.port", "%Cus:tcp.port", "udp.port", "%Cu:udp.port""
tshark: Invalid -o flag "column.format:No.,%m, tcp.port, %Cus:tcp.port,
udp.port, %Cu:udp.port"

Why don't I get messages for the following typo's?
$ tshark -r test.pcap -R "frame.number<6" -o column.format:""No.","%m",
"tcp.port", "%Cus:tcp.port", "udp.port", "%Cust:udp.port""
  1
  2
  3 1685,80
  4 80,1685
  5 1685,80

$ tshark -r test.pcap -R "frame.number<6" -o column.format:""No.","%m",
"tcp.port", "%Cus:tcp.port", "udp.port", "%Custttttttttttttt:udp.port""
  1
  2
  3 1685,80
  4 80,1685
  5 1685,80

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching all bug changes.