Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] tshark -T fields and info column

From: "Starner, Mark" <mark.starner@xxxxxxxxxx>
Date: Sun, 25 May 2008 08:11:07 -0500
It is just me, or does the Windows version of tshark not support this option? 

I have seen this posted a lot, but I get an error when I try to use it.

Thanks
Mark Starner

-----Original Message-----
From: wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Stig Bjørlykke
Sent: Sunday, May 25, 2008 6:24 AM
To: Community support list for Wireshark
Subject: Re: [Wireshark-users] tshark -T fields and info column

On 24. mai. 2008, at 20.25, wireshark@xxxxxxxxxxxx wrote:

> Is it possible with tshark to output the regular column info (I'm 
> interested in the %i info field in particular) while also outputting 
> fields using -T fields with -e.


You can overwrite the column format with custom columns like this:

tshark -o column.format:'"No.", "%m", "Info", "%i", "Len", "%Cus:tcp.len"'


--
Stig Bjørlykke


_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
http://www.wireshark.org/mailman/listinfo/wireshark-users

Attachment: smime.p7s
Description: S/MIME cryptographic signature