Folks,
The (-d , ) option with tshark tells tshark to interpret packets on the
specified port as the given protocol. Is there a way to provide a range of
ports using this route?
Also, is wireshark does not seem to allow this command line otion. Is there
some way to do the same other than
Folks,
tshark display format includes data for all the protocols decoded (e.g
etherner, IP, UDP/TCP and application layer protocol) in the stack.
Is there a way by which I can specify that I only want to see data for a
given protocol layer e.g app. layer only (for which I have a custom