This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Tshark command

0

Hi All,

How to disable/enable the protocols using tshark commands? Could you tell me the ASAP.

Regards, Swathi.

asked 14 Mar '16, 02:26

swathi%20jakkam's gravatar image

swathi jakkam
6778
accept rate: 0%

In the context of your other recent questions, I suspect you are actually seeking ways to reduce the amount of data which Tshark has to process so that you would be able to handle longer (in terms of time) captures. Is this suspicion correct?

(14 Mar '16, 03:29) sindy

One Answer:

0

Assuming you use Wireshark 2.0.x, you can use the --disable-protocol option as found in the man page.

You can also manually edit the disabled_protos file as described in the same man page. It is applicable fro all Wireshark releases as far as I know.

answered 14 Mar '16, 03:23

Pascal%20Quantin's gravatar image

Pascal Quantin
5.5k1060
accept rate: 30%

edited 14 Mar '16, 06:50