ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: [Wireshark-users] Tshark and using display filters

From: "Irakli Natshvlishvili" <iraklin@xxxxxxxxx>
Date: Fri, 4 May 2007 12:14:14 -0800
I have a capture file, want to use tshark to filter packets and write a new file.

When I use

tshark -r all.cap -w filtered.cap -R udp contains "100"

'I'm getting

tshark Read filters were specified both with "-R" and with additional command-line arguments

Platform is XP with SP2. What I'm doing wrong?

--
I.N.