[GTALUG] Wireshark question -- script to extract data in TCP stream?

James Knott james.knott at rogers.com
Tue Sep 26 19:37:50 EDT 2017


On 09/26/2017 09:55 AM, William Park via talk wrote:
>> Doesn't following stream in Wireshark also capture both directions? 
>> > Perhaps, after exporting, you could filter out what you need.
> How to filter it using Wireshark/Tshark/etc?  :-)
> I can filter after-the-fact, but it's messy.

I'm not sure you can filter direction on a stream.  I'd think a stream
would include both sides by definition.



More information about the talk mailing list