Wireshark-users: Re: [Wireshark-users] Unique filters
From: "Robert D. Scott" <[email protected]>
Date: Mon, 30 Nov 2009 11:40:32 -0500
Just run tshark from CYGWin and pipe it to sort -u.

Robert D. Scott                 [email protected]
Senior Network Engineer         352-273-0113 Phone
CNS - Network Services          352-392-2061 CNS Phone Tree
University of Florida           352-392-9440 FAX
Florida Lambda Rail             352-294-3571 FLR NOC
Gainesville, FL  32611          321-663-0421 Cell


-----Original Message-----
From: [email protected]
[mailto:[email protected]] On Behalf Of Kevin Cullimore
Sent: Monday, November 30, 2009 11:33 AM
To: Community support list for Wireshark
Subject: Re: [Wireshark-users] Unique filters

Nicole Powell wrote:
> Is there a similar command for the Windows version?
It may be possible to write something using powershell. The utilities 
found here claim to provide similar functionality (DISCLAIMER: untested).
http://btravan.com/mediawiki-1.6.8/index.php?title=Windows_cli_tools

>
> From the desk of Nicole  A. Powell.....
>  
>
>
>
>
>
> ------------------------------------------------------------------------
> From: [email protected]
> To: [email protected]
> Date: Thu, 29 Oct 2009 10:43:04 -0400
> Subject: Re: [Wireshark-users] Unique filters
>
> If you're running on linux, I believe you can pipe it to sort with the 
> unique switch:
>
>        
>
> <tshark command> | sort -u
>
>  
>
>  
>
> *From:* [email protected] 
> [mailto:[email protected]] *On Behalf Of *Nicole 
> Powell
> *Sent:* Thursday, October 29, 2009 8:08 AM
> *To:* [email protected]
> *Subject:* [Wireshark-users] Unique filters
>
>  
>
>
> How can I create a filter that displays only unique packets (i.e., I 
> want to look at all the beacon frames but I don't want to see any 
> duplicates)?
>
>  
>
>
> ------------------------------------------------------------------------
>
>
___________________________________________________________________________
> Sent via:    Wireshark-users mailing list <[email protected]>
> Archives:    http://www.wireshark.org/lists/wireshark-users
> Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
>
mailto:[email protected]?subject=unsubscribe

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <[email protected]>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
 
mailto:[email protected]?subject=unsubscribe