I basically want to type in a string to search a raw capture within Linux vs GUI. How is the possible? what are all the commands(within reason)? asked 17 May '13, 13:14 Vurcos |
One Answer:
You could try the following display filter:
either in the Wireshark GUI, or as value to the parameter "-R" when running tshark, e.g. If you use quotation marks within a filter on the command line you need to escape them with a backslash, as seen in the example. answered 17 May '13, 17:00 Jasper ♦♦ |