[Windump] how to see packet data appropriate what we want??

Gianluca Varenni gianluca.varenni at cacetech.com
Tue Aug 18 08:24:09 PDT 2009


>From what I understand, you would like windump to print out only some specific field in some specific format. Windump is pretty fixed in that regard, you cannot change the fields that get printed. You can change the verbosity with -v -vv and such, but you cannot change much more.

I would probably use tshark (or maybe even tshark) from the wireshark package. As far as I know they allow you to choose which fields will be printed. I'm not an expert with those utilities, so I suggest you to ask on the wireshark-users mailing list.

Hope it helps
GV

  ----- Original Message ----- 
  From: Aulia CS 
  To: windump at winpcap.org 
  Sent: Monday, August 17, 2009 11:45 AM
  Subject: [Windump] how to see packet data appropriate what we want??





        hello every body,,,,!!!

        can windump to see packet data appropriate what we want? for wxample, i want to capture packet that only "length n : ip_source > ip_dest", so the other packet like time, mac, packet data are not seen.

        thanks for every think,,,, 


------------------------------------------------------------------------------
  Berselancar lebih cepat. 
  Internet Explorer 8 yang dioptimalkan untuk Yahoo! otomatis membuka 2 halaman favorit Anda setiap kali Anda membuka browser.Dapatkan IE8 di sini! (Gratis)


------------------------------------------------------------------------------


  _______________________________________________
  Windump mailing list
  Windump at winpcap.org
  https://www.winpcap.org/mailman/listinfo/windump
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://www.winpcap.org/pipermail/windump/attachments/20090818/a8f65469/attachment.htm 


More information about the Windump mailing list