ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-dev: Re: [Wireshark-dev] [Wireshark-commits] rev 34186: /trunk/ /trunk/epan/: column-

From: Sake Blok <sake@xxxxxxxxxx>
Date: Tue, 5 Oct 2010 22:19:29 +0200
On 5 okt 2010, at 21:06, Stig Bjørlykke wrote:

> On Wed, Sep 22, 2010 at 10:56 PM,  <sake@xxxxxxxxxxxxx> wrote:
>>  When using a custom column, make it possible to select which occurrence to show if the field has multiple occurrences.
> 
> Did this change also change the output from "tshark -Tfields -e ip.addr"?
> Do we have to add support for "-e ip.addr[1]"?

Nope, tshark -T fields and wireshark are now not totally in sync. In tshark you can select the first, last or all occurrences, but only for all fields at once. Of course one can use the normal column output for specific references. However, it would be better to have the -T fields option take something like ip.addr[1] indeed.

There is always stuff to work on more than there is time to work on the stuff ;-)

Cheers,


Sake