DesertShark2
asked on
tshark capture filter
Hello:
I would like a capture filter that allows me to capture everything *except* the data payload. I want all the header, frame and protocol stuff, just not the data.
Kind of like 'tshark -i eth0 -V -EXCLUDE_DATA_PAYLOAD > capture.txt
Does anyone know how to do this?
I would like a capture filter that allows me to capture everything *except* the data payload. I want all the header, frame and protocol stuff, just not the data.
Kind of like 'tshark -i eth0 -V -EXCLUDE_DATA_PAYLOAD > capture.txt
Does anyone know how to do this?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Hey DesertShark2 . . . I am lazy and that seemed easier to me than having to define IP vs TCP vs UDP vs SMB vs SIP vs STP vs IGMP vs etc, etc, etc headers and the precision it would require.
Good luck,
Steve "Mr Lazy"
Good luck,
Steve "Mr Lazy"
ASKER
Wow, it was so easy all along...thanks!
ASKER