By now , i've read up on some of Sake's Blok and Joke Snelders' work and this looks promising:
tshark -r test.pkt -q -z io,stat,300,COUNT"(ip.dsfield.dscp)ip.dsfield.dscp&&ip.dsfield.dscp==48",COUNT"(ip.dsfield.dscp)ip.dsfield.dscp&&ip.dsfield.dscp==46",COUNT"(ip.dsfield.dscp)ip.dsfield.dscp&&ip.dsfield.dscp==34",COUNT"(ip.dsfield.dscp)ip.dsfield.dscp&&ip.dsfield.dscp==32",COUNT"(ip.dsfield.dscp)ip.dsfield.dscp&&ip.dsfield.dscp==26",COUNT"(ip.dsfield.dscp)ip.dsfield.dscp&&ip.dsfield.dscp==24",COUNT"(ip.dsfield.dscp)ip.dsfield.dscp&&ip.dsfield.dscp==18",COUNT"(ip.dsfield.dscp)ip.dsfield.dscp&&ip.dsfield.dscp==16",COUNT"(ip.dsfield.dscp)ip.dsfield.dscp&&ip.dsfield.dscp==10",COUNT"(ip.dsfield.dscp)ip.dsfield.dscp&&ip.dsfield.dscp==8",COUNT"(ip.dsfield.dscp)ip.dsfield.dscp&&ip.dsfield.dscp==4",COUNT"(ip.dsfield.dscp)ip.dsfield.dscp&&ip.dsfield.dscp==0"
now lets check if the values found are the right amounts ...
answered 17 Sep '15, 08:15
Marc
147●10●13●16
accept rate: 27%
Right, so the values check out, now i've worked it over > 580 traces, got a substantial txt doc,
0.0 <> 118.9 | 5602 | 4024 | 9096 | 0 | 7162 | 0 | 56 | 0 | 0 | 0 | 0 | 1814545 |
did a FIND for
0.0 <>
then a copy results to new file in PSPAD, use the|
as a delimiter to work it in a spreadsheet .. .. hmm , i might just start marking my own comment as an answer ..