| I'm using this command: Where "and" is actually "&&". This works with tshark v. 1.10, but v. 1.15 says: So I started to try ostensibly equivalent capture filters, but failed right away -- the  How can I get this functionality of v. 1.10 in the newer 1.15? asked 22 Apr '15, 00:50 mk27 | 
One Answer:
| Why the desire for two-pass analysis anyway? Dissecting IP and the IP sources address does not need it, neither does the IP length. So I would suggest skipping the '-2' parameter and check your results. answered 22 Apr '15, 02:36 Jaap ♦ 
 (22 Apr '15, 06:37) mk27 And  (22 Apr '15, 06:53) mk27 | 
 
          
1.15? Where did you get that version from?