Link to home
Start Free TrialLog in
Avatar of CousinDupree
CousinDupreeFlag for United States of America

asked on

Need help with a tshark filter.

I am using Wireshark to capture network traffic to a file, using the filter 'no arp no broadcast no multicast host 10.20.30.40'.  I would like to use tshark to do the capture to a file instead.  This same filter generates errors when it is used in tshark.  What would the equivalent Tshark filter be?
ASKER CERTIFIED SOLUTION
Avatar of Hugh Fraser
Hugh Fraser
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of CousinDupree

ASKER

My apologies, 'not arp and not broadcast and not multicast and host 10.20.30.40' is indeed the filter that I am using.  It doesn't work in Tshark, however.
This is the correct syntax for the filter, if that's where the problem is. What error are you getting?
My command line syntax was incorrect, your answer was correct..  Thanks for the help!