hello everyone im trying to capture just a TCP files with TSHARK.
tshark -g -s 65535 -b duration:43200 -a files:1 -i eth0 –I eth1 -w /home/pi/DATA/info
im using this right now and want to add a filter
asked 08 Oct '17, 17:53
You can add capture filter to tshark with '-f pcap-filter-expr' (s. also https://wiki.wireshark.org/CaptureFilters).
To filter only tcp packets, use '-f tcp'
answered 09 Oct '17, 00:57