Tshak
只看解析部分
用法
shell
tshark [ -i <capture interface>|- ] [ -f <capture filter> ] [ -2 ] [ -r <infile> ] [ -w <outfile>|- ] [ options ] [ <filter> ]
tshark -G [ <report type> ] [ --elastic-mapping-filter <protocols> ]打印报文
shell
tshark -r $1 -T fields -e ip.src -e ip.dst -e ip.proto -e tcp.srcport -e tcp.dstport过滤报文
shell
tshark -Y "tcp.port == 58125" -r 1.pcap