tshark provides
This works fine on windows build. However -Y is an invalid option on linux build.
From
asked 23 Jan ‘17, 19:07 wire990099 edited 23 Jan ‘17, 20:25 |
One Answer:
-R filters packets during the first pass of analysis. -Y filter packets on single-pass dissect. "Normally" on a current tshark (2.2.X) you would use -Y. However your tshark version is pretty old (1.8.10). Here you have to use -R. -Y has been introduced with 1.10.X answered 24 Jan '17, 02:04 Uli |