Tshark -e specific bytes of a frame or protocol



The gsm_a.rp dissector does not implement filter on rp_cause (22,"Memory capacity exceeded" eg) which I beleive the most important element of this protocol in case of an RP-ERROR. In wshark can filter by frame[x:y] so would it be possible to use tshark -e frame[x:y] in any way? Or alternatively is it possible to modify the gsm_a.rp dissector to include rp_cause?

Thanks, PeterK

