I using Wireshark on Ubuntu 12.04 and whenever i type in the field such as -e col.Protocol , col.Info etc.. i could not get any result display on text editor or csv file. Anyone know what is the problem? asked 06 May '14, 19:54 tch |
2 Answers:
So the answer to your question is simple. Version 1.6.7 doesn't support answered 09 May '14, 17:41 cmaynard ♦♦ |
As of the 1.11.x and 1.12 versions of tshark, the field names are "_ws.col.Protocol" and "_ws.col.Info", instead of "col.Protocol" and "col.Info". Example:
Source: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10201 answered 19 Jun '14, 16:50 CraigGarrett edited 20 Jun '14, 10:21 |
Which version of Wireshark are you using?
wireshark 1.6.7 is it the latest? Sorry for asking so much as i am new to it
No, Wireshark 1.6.7 is most definitely not the latest available version. The latest releases as of this writing are:
You can download them from http://www.wireshark.org/download.html.
The 1.6 branch went End-Of-Life on June 7, 2013. Refer to the LifeCycle page for more information about End-Of-Life planning.