Wireshark-users: Re: [Wireshark-users] Filtering multiple VLAN tags
From: "NEWMAN Christopher" <Christopher.Newman@xxxxxxxxxxxxxxxxxx>
Date: Mon, 29 Sep 2008 12:15:17 -0500
I guess nobody knows...  :(

Anybody have an idea of where I can find the answer to my question?  The
documentation didn't seem to cover it.

Thanks,
Chris


-----Original Message-----
From: wireshark-users-bounces@xxxxxxxxxxxxx
[mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of NEWMAN
Christopher
Sent: Thursday, September 25, 2008 4:53 PM
To: wireshark-users@xxxxxxxxxxxxx
Subject: [Wireshark-users] Filtering multiple VLAN tags

Hello all,

I'm using tshark to parse a captured packet.  Most fields are easy to
grab, but I can't figure out how to grab both VLAN tags from a stacked
Ethernet frame.  The following command returns the inner (2nd) VLAN ID:

     tshark -r test.pcap -c 1 -T fields -e vlan.id

I tried using vlan.id[0], vlan[0].id, etc. to no avail.  I also tried
the following, which returns nothing in the first column and the inner
VLAN in the second column:

     tshark -r test.pcap -c 1 -T fields -e vlan.id -e vlan.id

I know tshark can process the fields correctly because the detailed XML
and verbose options show both VLANs parsed out.  I could parse those
outputs, but I really don't want to do it that way.

Does anyone know how to specify field names so I can retrieve multiple
instances of the same field?

Thanks in advance.

Chris
_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
https://wireshark.org/mailman/listinfo/wireshark-users