3 ms·
Apologies for "well, actually"-ing here, but the capture part of Wireshark is dumpcap and the various extcap utilities (sshdump, ciscodump, etc). TShark is the
by geraldcombs 5y ago
Apologies for "well, actually"-ing here, but the capture part of Wireshark is dumpcap and the various extcap utilities (sshdump, ciscodump, etc). TShark is the command line interface to Wireshark's dissection engine, which, as you point out can be a really useful thing to have. It ships with a bunch of other command line utilities as well, such as editcap, mergecap, and capinfos: https://www.wireshark.org/docs/man-pages/ https://www.wireshark.org/docs/man-pages/
- nonrandomstring 5y ago> sshdump Thanks for that handy one I'd missed until now!