Ask Your Question

Revision history [back]

Nope, it's simply a count of the number of packets in the current capture file. In the documentation value is a placeholder for the number of packets.

There are no options to switch to the next file based on what's in the packets as dumpcap doesn't do dissection. Even if using tshark, which does dissect, there are no options to switch to the next file based on packet contents, mainly because it uses the same code as dumpcap.