Re: [Wireshark-users] Filter existing file

2008-01-22 Thread Kuhs Lukas
Thanks Jeff, thanks Stephen!
Lukas

-- 
  --
--

   Lukas KUHS
   Alcatel Lucent Deutschland AG
   Mobile Stuttgart, Multi-Standard (WiMAX)
 
--
  --
--


Alcatel-Lucent Deutschland AG 
Sitz der Gesellschaft: Stuttgart - Amtsgericht Stuttgart HRB 4026
Vorsitzender des Aufsichtsrats: Michael Oppenhoff
Vorstand: Wolfgang Weik (Vors.), Dr. Rainer Fechner, Juergen Poesinger,
Alf
Henryk Wulf
 

> -Original Message-
> From: [EMAIL PROTECTED] 
> [mailto:[EMAIL PROTECTED] On Behalf Of 
> Jeff Morriss
> Sent: Dienstag, 22. Januar 2008 17:11
> To: Community support list for Wireshark
> Subject: Re: [Wireshark-users] Filter existing file
> 
> 
> 
> Kuhs Lukas wrote:
> > Hi,
> > 
> > I want to filter an existing pcap-file using dumpcap on 
> Windows. This is
> > not possible since there is no infile option anymore. 
> Tethereal had this
> > option. My question is, whether this will be included in a 
> later version
> > or not. Do you know any workaround except for using 
> tethereal? I need to
> > execute it on the command line.
> 
> dumpcap is only a capturing tool.  If you want to filter or 
> do analysis, 
> better use tshark (it's the equivalent of tethereal after the 
> name change).
> ___
> Wireshark-users mailing list
> Wireshark-users@wireshark.org
> http://www.wireshark.org/mailman/listinfo/wireshark-users
> 
___
Wireshark-users mailing list
Wireshark-users@wireshark.org
http://www.wireshark.org/mailman/listinfo/wireshark-users


Re: [Wireshark-users] Filter existing file

2008-01-22 Thread Stephen Fisher
On Tue, Jan 22, 2008 at 04:39:19PM +0100, Kuhs Lukas wrote:

> I want to filter an existing pcap-file using dumpcap on Windows. This 
> is not possible since there is no infile option anymore. Tethereal had 
> this option. My question is, whether this will be included in a later 
> version or not. Do you know any workaround except for using tethereal? 
> I need to execute it on the command line.

Have you tried using tshark?  It is the new version of tethereal.


Steve

___
Wireshark-users mailing list
Wireshark-users@wireshark.org
http://www.wireshark.org/mailman/listinfo/wireshark-users


Re: [Wireshark-users] Filter existing file

2008-01-22 Thread Jeff Morriss


Kuhs Lukas wrote:
> Hi,
> 
> I want to filter an existing pcap-file using dumpcap on Windows. This is
> not possible since there is no infile option anymore. Tethereal had this
> option. My question is, whether this will be included in a later version
> or not. Do you know any workaround except for using tethereal? I need to
> execute it on the command line.

dumpcap is only a capturing tool.  If you want to filter or do analysis, 
better use tshark (it's the equivalent of tethereal after the name change).
___
Wireshark-users mailing list
Wireshark-users@wireshark.org
http://www.wireshark.org/mailman/listinfo/wireshark-users