Is there a way to use wireshark/tshark with options to generate the "analyze->expert info" output for an input/existing PCAP file? thanks asked 07 Feb '13, 16:32 donlex |
One Answer:
Unfortunately that functionality is not implemented. The best you can do is this:
and/or
Regards answered 07 Feb '13, 16:44 Kurt Knochner ♦ edited 08 Feb '13, 02:02 |
The development version does have a tshark tap for this. e.g.
tshark -2 -r input.pcap -zexpert,<min-severity> -q
where min-severity can be error error | warn | note | chat
hm.. that option is already in the version 1.8.x. See my first example in the answer. Is the output different in the development version?
Oops, sorry, I didn't spot that your first example already uses it, and hadn't checked that it was already in 1.8. There have been no changes to the code for this since the 1.8 branch was created, so the form of the output would be the same.
If the functionality that the question wanted is not implemented, what is it that they are looking for?
good question. Let's wait for an update of the OP.