OSQA is unmaintained. Help us figure out where to go from here.

I created a Tshark script, I realized that I am only filtering incoming messages so I can not see anything. Can someone help me?

Tshark.exe -i rpcap://[172.16.254.6]/\Device\NPF_{CF9CFF46-79FF-4A97-802A-F6CEF5896D29} -f "tcp[20:4]=0x383D4649 and tcp[24:1]=0x58" -i rpcap://[172.16.254.6]/\Device\NPF_{0E94BE7D-D6F0-43B0-B561-5CE3FC9A6AD7} -f "tcp[20:4]=0x383D4649 and tcp[24:1]=0x58" -w "D:\fix\%DATE:~4,2%%DATE:~7,2%%DATE:~10,4%_APP01.pcap"

asked 29 Jun, 11:17

JorgeMiguelr210's gravatar image

JorgeMiguelr210
636
accept rate: 0%

edited 29 Jun, 11:19


I may be wrong nowadays, but the last time I've tried a couple of months ago, you could capture from just a single input queue. If this is still true, to achieve your goal, you'll have to run two instances of tshark, each capturing from another remote device, and then merge the result files.

permanent link

answered 29 Jun, 12:12

sindy's gravatar image

sindy
6.0k3850
accept rate: 25%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×1,611
×828
×344

question asked: 29 Jun, 11:17

question was seen: 257 times

last updated: 29 Jun, 12:12

p​o​w​e​r​e​d by O​S​Q​A