Wireshark-users: Re: [Wireshark-users] Need filters
From: "David H. Lipman" <DLipman@xxxxxxxxxxx>
Date: Wed, 23 Jun 2010 17:53:23 -0400
From: "Jaap Keuter" <jaap.keuter@xxxxxxxxx>

| On 06/23/2010 11:00 PM, David H. Lipman wrote:

>> The server admin provided the following to me Today...

>> "I record pcap with tshark, so what I need is a tshark capture filter."



| Hi,

| Well then, tell him to add:
| -f "not udp port 137" to the tshark command line.

Command Line switches are not a god idea as this is only the beginning of filtering out 
process.

Does TShark interpret a disk file with these directives ?


-- 
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp