Ask Your Question

how I change tshark maximum number of fields allowed in template?

asked 2018-03-06 01:01:05 +0000

this post is marked as community wiki

This post is a wiki. Anyone with karma >750 is welcome to improve it.

The new cflow template is more than 60 fields. The default setting on tshark is 60. I need to change it else tshark will not able to interpret it. Which option should I use? I know how to do it on wireshark but not tshark.

Thx, Ted

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted

answered 2018-03-06 18:12:30 +0000

Jaap gravatar image

From the manual page, use -o <preference setting>. Then the question is: which preference? You can always look in your preferences file (use the About Wireshark dialog box to easily find it). In this case it's cflow.max_template_fields, so that becomes -o cflow.max_template_fields:60, or whatever value you want to set it to.

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2018-03-06 01:01:05 +0000

Seen: 321 times

Last updated: Mar 06 '18