I stumbled across this link and found it potentially advantageous if I can learn how to use it:
My problem is that the filter here does not work.
I am simply trying to grab the lines that are ip only, just as I would if I were in Wireshark filtering "ip" of an existing pcap file.
asked 23 Nov '15, 09:08
I finally figured it out. There was nothing wrong with my file except a missing preference setting. It was apparently the preferences for Wireshark that needed to be set in order for it to properly filter the type of .pcap files I am using.
answered 23 Nov '15, 13:07
edited 23 Nov '15, 13:08
Then please try this:
There is no need to redefine the column formar, unless you are looking for something very special.
If you want to write a new pcap file, please try this
BTW: the correct format for gui.column.format would be:
answered 23 Nov '15, 09:31
Kurt Knochner ♦
edited 23 Nov '15, 10:30