Wireshark-users: Re: [Wireshark-users] Simultaneous use of capture and display filter while captu
From: Kevin <masonke@xxxxxxxxx>
Date: Thu, 28 May 2009 07:02:21 -0700
Why would you use the display filter?  Try -f "host 10.20.30.20 and tcp"

~KEM

On May 28, 2009, at 3:48 , Tapas Chatterjee wrote:

Hi,
 
Is it possible to use "-f" and "-R" simultaneously while capturing using tshark.
e.g tshark -i eth0 -f tcp -R "ip.src == 10.20.30.20" -w output.pcap
 
Thanks and Regards,
Praveen Jha
 


"DISCLAIMER: This message is proprietary to Aricent and is intended solely for the use of the individual to whom it is addressed. It may contain privileged or confidential information and should not be circulated or used for any purpose other than for what it is intended. If you have received this message in error,please notify the originator immediately. If you are not the intended recipient, you are notified that you are strictly prohibited from using, copying, altering, or disclosing the contents of this message. Aricent accepts no responsibility for loss or damage arising from the use of the information transmitted by this email including damage from virus."
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe