This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I have a huge file in the pcap format from a dumpcap capture. I am wanting to create a second file that only contains packets going to or from a certain range of MAC address. So I tried doing something like this:

dumpcap -f 'eth.src[0:3] == 90:21:55 || eth.dst[0:3] == 90:21:55' -w htc.pcap -i - < wlan1.pcap

But when I do, the resulting file is the same as the input. The filter syntax works fine in wireshark; is there a different filter syntax that I need to use for dumpcap? Does the dumpcap filter not work when reading from stdin?

I'm using Dumpcap 1.2.11 from Ubuntu 10.10

Thanks!

asked 23 Jan '11, 11:26

unraveled's gravatar image

unraveled
1111
accept rate: 0%


I think the problem is that -f is a capture filter syntax & you are using a display filter. I think currently Dumpcap only works with capture filters. What about trying tshark with the filter starting -R instead of -f. This will allow you to read it in using the display filter syntax you have:-

tshark -r inputfile.pcap -R 'eth.src[0:3] == 90:21:55 || eth.dst[0:3] == 90:21:55' -w outputfile.pcap

permanent link

answered 23 Jan '11, 14:32

KeithFrench's gravatar image

KeithFrench
121115
accept rate: 0%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×349
×157
×89
×87
×3

question asked: 23 Jan '11, 11:26

question was seen: 5,317 times

last updated: 23 Jan '11, 14:32

p​o​w​e​r​e​d by O​S​Q​A