Wireshark-dev: Re: [Wireshark-dev] Feature Request for EDITCAP - Selecting by IP Address and Po
From: "J P" <[email protected]>
Date: Wed, 30 Jan 2008 12:26:17 -0600
Hi Everyone,
First of all this question should have never been asked here first - I should have posed this to the user forum first.
Secondly, after some of my own research I discovered that TShark is the tool that should be used.
Sorry for any inconvenience.

On Jan 30, 2008 10:13 AM, J P <[email protected]> wrote:
Would it be possible to add the following functionality to EDITCAP:
Select packets based on:
  • Select IP Address and Source Port
  • Select IP Address and Destination Port
  • As well as Start and End time of packets


  • Multiple Input Capture Files
The capture files are 250 Mb in size and is very time consuming to load and analyze.
What I need to do is to be able to extract out a specific VoIP call using UNISTIM that spans multiple capture files based on IP Address and Source and/or Destination Port and possible a within a specific time frame.
This extracted call would then be copied off for further analysis.
If this is poss
If you have any questions or require further information please let me know.