Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

Dumpcap/tshark hint on how to use -b filter

Hi,

reading dumpcap documentation https://www.wireshark.org/docs/man-pages/dumpcap.html I got interested in the buffer ring filter packet => "packets:value switch to the next file after it contains value packets.". Do you have any examples or hints on how to use it? Can I write pcap according to packets flags or header information?

Thank you in advance