Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

Best I can tell from the code, tshark does not support multiple -Y options - last one in wins.

case 'Y':
  dfilter = optarg;

Combine the -Y filters into one and add to the end to exclude the blank lines.

tshark -d tcp.port==1030,http -Y "ip.src== and tcp.srcport==1030 and http.request.method=='POST' and" -T fields -e -i vestas_sim_br