Wireshark-users: Re: [Wireshark-users] display text representation of ldap.filter in tshark
From: "j.snelders" <[email protected]>
Date: Thu, 14 Oct 2010 19:43:43 +0200
Hi Leo,

You can find an overview of all the available field names in the Display
Filter Reference:

You can also use ldap.filter as a display filter, use the option -V to add
the output of the packet tree (Packet Details) and send the output to a text
$ tshark -r ldap.pcap -R ldap.filter -V > ldap.txt

Hope this helps somehow

On Thu, 14 Oct 2010 15:47:43 +0200 Alexander 'Leo' Bergolth wrote:
>Is there a way to display the text representation of an ldap
>search-filter using tshark?
>I tried -e ldap.filter but this is only a 32 bit filter element (only
>the first filter element). Is there another display filter or a function
>that displays a human readable version of the whole search-filter?
