Hi, is there a reason why tshark does not offer the option -M (together with -D), comparable to dumpcap? dumpcap -D -M dumps the IP address of the interface, which is quite usefull to identify the right NIC, if there are several similar (or identical) ones in a machine. BTW: tshark does not complain about any unknown option (e.g. -M), if used after -D. tshark 1.7.1 Windows
tshark 1.6.2 Linux
Regards asked 07 May '12, 05:50 Kurt Knochner ♦ edited 07 May '12, 16:13 |
One Answer:
The option doesn't do anything in TShark and Wireshark as no-one has coded it yet. Please raise an enhancement request on Bugzilla. answered 07 May '12, 13:21 grahamb ♦ |
I just wanted to know if there is any special reason for that, before I raise an enhancement request.
Regards
Kurt
Personally I don't really need it as dumpcap is always available (tshark will just call dumpcap anyways). But I can see the wish for uniformity...