tshark udp conversation command
I am running: tshark -r file.pcap -q -z conv,udp. However, I get repeated conversations between some ip address pairs(send/response), same port pair. Can someone test the udp command and tell me what you get. If you know of a better way please let me know.
Works for me. You'll need to share a link to the capture that causes the issue for you. Upload the capture to a public file share, e.g. Google Drive, DropBox etc. and paste a link to the file in your question or as a comment.