how I change tshark maximum number of fields allowed in template?

asked 2018-03-06

The new cflow template is more than 60 fields. The default setting on tshark is 60. I need to change it else tshark will not able to interpret it. Which option should I use? I know how to do it on wireshark but not tshark.

Thx, Ted

answered 2018-03-06

Jaap

From the manual page, use -o <preference setting>. Then the question is: which preference? You can always look in your preferences file (use the About Wireshark dialog box to easily find it). In this case it's cflow.max_template_fields, so that becomes -o cflow.max_template_fields:60, or whatever value you want to set it to.

Asked: 2018-03-06

Last updated: Mar 06 '18