I'm using this command:
Where "and" is actually "&&". This works with tshark v. 1.10, but v. 1.15 says:
So I started to try ostensibly equivalent capture filters, but failed right away -- the How can I get this functionality of v. 1.10 in the newer 1.15? asked 22 Apr '15, 00:50 mk27 |
One Answer:
Why the desire for two-pass analysis anyway? Dissecting IP and the IP sources address does not need it, neither does the IP length. So I would suggest skipping the '-2' parameter and check your results. answered 22 Apr '15, 02:36 Jaap ♦
(22 Apr '15, 06:37) mk27 And (22 Apr '15, 06:53) mk27 |
1.15? Where did you get that version from?