Agreed Tshark will be helpful and more easy to implement wireshark filters. My understanding was Tshark is used with Java. Identical to Tcpdump for Perl. Definitely give a try to use Tshark in Perl. There's a Tshark PM too. I've been parsing input pcap file that don't contain mss option. here is the output with mss option.
Thank you
===output===
$VAR1 = { 'sack' => 2, 'mss' => 1460, 'ws' => 8 };
===output===
In reply to Re^4: filter tcpdump packets
by syboar
in thread filter tcpdump packets
by syboar
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |