This is our old Q&A Site. Please post any new questions and answers at

Hi Team,

I have a wireshark packet where two vlan headers are there. I would like to fetch individual vlan information using tshark on Linux environment, but seems not working properly.

tshark -Tfields -e vlan.priority frame.number==2 -r ft3088_1_ipv6_static_negative_propagation_port2_1_capture.pcap

Could suggest how to do this . Thanks in advance. The pcap file can be downloaded here

link text

asked 30 Jun '15, 00:20

udaya's gravatar image

accept rate: 100%


try below syntax

tshark.exe -T fields -e vlan.priority -Y frame.number==2 -r ft3088_1_ipv6_static_negative_propagation_port2_1_capture.pcap


permanent link

answered 30 Jun '15, 02:40

scheehan's gravatar image

accept rate: 100%

edited 30 Jun '15, 02:52

grahamb's gravatar image

grahamb ♦

Thanks. I tried the same but NOT working. I am with following tshark details. Is it related to version ..

    tshark: invalid option -- Y
TShark 1.0.8
Dump and analyze network traffic.
See for more information.
(30 Jun '15, 04:48) udaya

Can you not upgrade your version of tshark, 1.0.8 is pre-historic?

(30 Jun '15, 04:52) grahamb ♦

Or try substituting -R for -Y.

(30 Jun '15, 06:46) cmaynard ♦♦

Thanks I installed 1.6.7 and tried with -R worked perfect !!!


(30 Jun '15, 21:47) udaya
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 30 Jun '15, 00:20

question was seen: 2,296 times

last updated: 30 Jun '15, 21:47

p​o​w​e​r​e​d by O​S​Q​A