I'm using tshark extract smb.file information from a capture file. I have verified the the requested information is in the file using this wireshark filter:
However when using the following tshark filter I get no result:
can someone please provide some insight… Thanks asked 11 Oct '14, 12:39 dblk |
One Answer:
What happens if you use the filter
or
answered 11 Oct '14, 12:43 Guy Harris ♦♦ |
Guy thanks for the insight. Below is what worked:
Was this done with a Windows command line or a UN*X command line? The one with four backslashes might be required on UN*X.
It was done in mac os x terminal