ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: [Wireshark-users] tshark's -F option while capturing

From: "Zuidweg, R (Rob)" <zuidweg@xxxxxxxxxx>
Date: Fri, 10 Nov 2006 10:12:30 +0100
Title: Message
L.S.
 
 
I have been using ethereal/tethereal  for decoding OSI/CLNP traces and found the following problem.
While upgrading to suse 10.1 I found that tethereal 0.10.14  does not capture  in dos sniffer format using options : -i eth0  -w /tmp/shark.enc -Fngsniffer.
Output will be written in native pcap format. No error message is given.
 
Version 0.10.10 and 0.10.13 still work as expected.
 
For wireshark I do get a message:
zuidweg-10:/wireshark-0.99.4 # ./tshark -i eth0  -w /tmp/shark.enc -Fngsniffer
tshark: Live captures can only be saved in libpcap format.
 
My questions are :
 
- Why does the -F option no longer work ?
- any workaround/fix available ?
 
I was unable to find any notification so far in the documentation/FAQ. Did I overlook anything ? 
 
 
With kind regards,
 
Rob Zuidweg