Re: [Wireshark-users] tshark --print-a-specific-field ?

2007-05-30 Thread Douglas Pratley
Hi Guy Thanks for adding the documentation for -Tfields. The documentation for the -e / -E options was correctly added in the patch; it was only the -Tfields entry itself that I missed, and the current entry that points back to -e looks fine to me. Cheers Doug -Original Message- From:

[Wireshark-users] Bandwidth Utilization CSV??

2007-05-30 Thread Feeny, Michael \(GPCT-CAI\)
Hi. Is there a way to produce a bandwidth utilization table? That is, a table that would show bandwidth utilization as a function of time, over the course of a capture file? It looks like the Statistics / TCP Stream Graph / Throughput Graph provides this information (B/s over Time), but I have

[Wireshark-users] Capturing packets between 2 physical interfaces in same machine

2007-05-30 Thread Nagaraj Turaiyur
Hi- I just installed Wireshark version 0.99.5 on Windows XP. My laptop has 2 interfaces - ethernet wireless LAN. I want to capture packets sent between the 2 interfaces. I tried capture on either interface with default settings (promiscuous on), but I see only packets received from other

[Wireshark-users] Installation problem.

2007-05-30 Thread A Kumar, Vijay \(Vijay\)
Hi All, I am trying to install wireshark-0.99.5 on Solaris 9. I installed following packages. Downloaded from sunfreeware.com libpcap-0.9.5-sol9-sparc-local zlib-1.2.3-sol9-sparc-local glib-2.13.0-sol9-sparc-local gtk-2.2.4-sol9-sparc-local pcre-7.1-sol9-sparc-local libgcc-3.4.6-sol9-sparc-local

Re: [Wireshark-users] Capturing packets between 2 physical interfacesin same machine

2007-05-30 Thread Gianluca Varenni
Are you sure packets are actually transmitted on the wire/wireless and not just routed internally by the IP stack? GV - Original Message - From: Nagaraj Turaiyur To: wireshark-users@wireshark.org Sent: Wednesday, May 30, 2007 4:52 AM Subject: [Wireshark-users] Capturing

Re: [Wireshark-users] Installation problem.

2007-05-30 Thread Gerald Combs
A Kumar, Vijay (Vijay) wrote: But make is now creating problem. After executing make I am getting following error messages. Root # /usr/ccs/bin/make /usr/bin/perl ./make-version.pl . Version configuration file version.conf not found. Using defaults. This is not a SVN build. svnversion.h

[Wireshark-users] Comparing packets

2007-05-30 Thread Piers Kittel
Hello all, I'm trying to export data as a CSV file but I need to modify the data it exports a bit so I can do clever graphy things with it. My main problem is the H.261 packets in a bunch of files I've got. When I apply a filter (h261.stream) it shows all the packets I'm interested in,

Re: [Wireshark-users] Bandwidth Utilization CSV??

2007-05-30 Thread Stephen Fisher
On Wed, May 30, 2007 at 07:19:33AM -0400, Feeny, Michael (GPCT-CAI) wrote: Hi. Is there a way to produce a bandwidth utilization table? That is, a table that would show bandwidth utilization as a function of time, over the course of a capture file? The bandwidth utilized in both

[Wireshark-users] dcerpc.cn_call_id display filter problem when reassembled PDU

2007-05-30 Thread andre.noel
Hi, I captured DCERPC traffic and then I did a filter to isolate a particular call ID with that filter : dcerpc.cn_call_id == 96 I went trough that problem: When selecting the option Allow subdissector to reassemble TCP streams checked the filter catches only the Request. When

[Wireshark-users] SSL Question

2007-05-30 Thread al aghili
Hi, I would like to run tshark to capture encrupted ssl messages so I can read off of standard out and decrypt it using our certificate. But when I run a command like this. C:\Program Files\Wiresharktshark -i 2 -R ssl.app_data -T text -V -l -d tcp.port==8443,ssl The application data dump

[Wireshark-users] Apple Mac OS X crash on start

2007-05-30 Thread Mark Boltz
Hi folks, I'm trying to build Wireshark on an Apple MacBook Pro running OS X 10.4.9. Here's my wireshark --version output: enterprise:~/Documents mboltz$ wireshark --version wireshark 0.99.5 Copyright 1998-2007 Gerald Combs [EMAIL PROTECTED] and contributors. This is free software; see

Re: [Wireshark-users] dcerpc.cn_call_id display filter problem when reassembled PDU

2007-05-30 Thread Sake Blok
On Wed, May 30, 2007 at 03:34:29PM -0400, [EMAIL PROTECTED] wrote: I captured DCERPC traffic and then I did a filter to isolate a particular call ID with that filter : dcerpc.cn_call_id == 96 I went trough that problem: When selecting the option Allow subdissector to reassemble TCP

[Wireshark-users] Installation problem.

2007-05-30 Thread A Kumar, Vijay \(Vijay\)
Hi All, I am trying to install wireshark-0.99.5 on Solaris 9. I installed following packages. Downloaded from sunfreeware.com libpcap-0.9.5-sol9-sparc-local zlib-1.2.3-sol9-sparc-local glib-2.13.0-sol9-sparc-local gtk-2.2.4-sol9-sparc-local pcre-7.1-sol9-sparc-local libgcc-3.4.6-sol9-sparc-local

Re: [Wireshark-users] having trouble compiling wireshark

2007-05-30 Thread Guy Harris
Rohit Grover wrote: I've installed libpcap 0.9.5 (from source) on my debian system and done a 'make install' to setup libpcap.a. But I get the following error when running ./configure for wireshark (0.99.5): ... checking pcap.h usability... yes checking pcap.h presence... yes checking