Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: Re: [Wireshark-dev] tshark: drop features "dump to stdout" and"read filter" - co

From: Jeff Morriss <jeff.morriss.ws@xxxxxxxxx>
Date: Wed, 10 Oct 2007 09:47:08 -0400


Maynard, Chris wrote:
FYI: I was able to test this on a Windows PC, but it doesn't appear to be working.  I could be doing something wrong since I hardly ever use tshark, but I compared the output of a 0.99.6-tshark with the output of an SVN-23125-tshark with the following command line:

When using "-w -" you're telling tshark to write the *PCAP* data to stdout so normally I'd do:

tshark -w - > /some/file

And then:

tshark -r /some/file

to read it back in/display it.