This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hello,

In short:

tshark dst port 80 -Y http.request -T fields -e http.host -e http.user_agent > http_dumpfile &

tshark dst portrange 21-22 -Y "ftp.request.command == LIST || ftp.request.command == PASV" -T fields -e ftp.request.command -e ftp.request.arg > ftp_dumpfile &

tshark "dst port 143 or dst port 220" -Y imap.isrequest==1 -T fields -e imap.request.command > imap_dumpfile &

vs one long:

tshark "dst port 80 or dst port 110 or dst port 220 or dst portrange 21-22" -Y "ftp.request.command == LIST || ftp.request.command == PASV || http.request || imap.isrequest==1" > capture_dumpfile

-----

Longer version: Writing some program in python that uses tshark to capture and analyze some traffic. Using specific capture filters in a combination of display filters to minimize the output as much as possible.

Now I have to decide if I'll use several instances of tshark with different capture filters and display filters VS Running unified more complex capture filter and then analyze the traffic programmatically?

Very important note is that Display Filters ease by work significantly.

asked 04 Sep '15, 05:56

Do5's gravatar image

Do5
1111
accept rate: 0%


Now I have to decide if I'll use several instances of tshark

besides the fact that the sum of the short tshark commands is different than the long tshark command, you can choose whatever method you like better or which causes less work in your script that parses the output. I don't see a direct advantage/disadvantage of having three short tshark commands versus on large.

Regards
Kurt

permanent link

answered 07 Sep '15, 16:40

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×832
×55
×5
×4

question asked: 04 Sep '15, 05:56

question was seen: 2,139 times

last updated: 07 Sep '15, 16:40

p​o​w​e​r​e​d by O​S​Q​A