Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.networking > #1207 > unrolled thread
| Started by | "ghand" <ghand45@hotmail.com> |
|---|---|
| First post | 2012-03-25 08:32 +0100 |
| Last post | 2012-03-25 10:00 +0100 |
| Articles | 3 — 2 participants |
Back to article view | Back to comp.os.linux.networking
documentation for tcpdump "ghand" <ghand45@hotmail.com> - 2012-03-25 08:32 +0100
Re: documentation for tcpdump Ralph Spitzner <rasp@spitzner.org> - 2012-03-25 09:22 +0200
Re: documentation for tcpdump "ghand" <ghand45@hotmail.com> - 2012-03-25 10:00 +0100
| From | "ghand" <ghand45@hotmail.com> |
|---|---|
| Date | 2012-03-25 08:32 +0100 |
| Subject | documentation for tcpdump |
| Message-ID | <4f6ebc0b$1@x-privat.org> |
I am a bit baffled re documentation for tcpdump. I cannot figure out what the main source is.. I read that it is the man page.. But I just don't see things there that I do see elsewhere. For example This link http://www.tcpdump.org/#documentation it says "Full documentation is provided with the source packages in man page format. People with Windows distributions are best to check the Windows PCAP page for references to WinDUMP. What follows are the man pages formatted in HTML (using man2html) and some tutorials written by external contributors." So that suggests that it's all in the man page Here is the man page http://www.tcpdump.org/tcpdump_man.html But in articles written by external contributors, I see many things not in there. e.g. This great article mentioned http://www.cs.ucr.edu/~marios/ethereal-tcpdump.pdf Tcpdump filters, by Marios Iliofotou says there are three different kinds of qualifier. type, dir, proto When I go to the man page, I don't see the word "qualifier" The man page does not mention the keyword portrange But it is mentioned here http://www.msamir.net/the-art-of-network-debugging-with-tcpdump/ So where are the third party people getting the info from? Is the man page the main source and if so, where is the missing stuff? Is there perhaps some other main documentation source by the tcpdump authors themselves?
[toc] | [next] | [standalone]
| From | Ralph Spitzner <rasp@spitzner.org> |
|---|---|
| Date | 2012-03-25 09:22 +0200 |
| Message-ID | <2nt249-4eg.ln1@spitzner.org> |
| In reply to | #1207 |
ghand wrote:
> there are three different kinds of qualifier.
> type, dir, proto
>
> When I go to the man page, I don't see the word "qualifier"
>
> The man page does not mention the keyword portrange
> But it is mentioned here
> http://www.msamir.net/the-art-of-network-debugging-with-tcpdump/
Are you referring to:
expression
selects which packets will be dumped. If
no expression is given, all packets on the net will
be dumped.
Otherwise, only packets for which expression is `true'
will be dumped.
For the expression syntax, see pcap-filter(7).
???
-rasp
--
See why I hate Windows users?
All pain, no gain.
-Howard Chu
[toc] | [prev] | [next] | [standalone]
| From | "ghand" <ghand45@hotmail.com> |
|---|---|
| Date | 2012-03-25 10:00 +0100 |
| Message-ID | <4f6ed0aa$1@x-privat.org> |
| In reply to | #1209 |
Ralph Spitzner <rasp@spitzner.org> wrote: >ghand wrote: >> there are three different kinds of qualifier. >> type, dir, proto >> >> When I go to the man page, I don't see the word "qualifier" >> >> The man page does not mention the keyword portrange >> But it is mentioned here >> http://www.msamir.net/the-art-of-network-debugging-with-tcpdump/ > >Are you referring to: > >expression > selects which packets will be dumped. If > no expression is given, all packets on the net will > be dumped. > Otherwise, only packets for which expression is `true' > will be dumped. > > For the expression syntax, see pcap-filter(7). > >??? > -rasp > > thanks, well spotted
[toc] | [prev] | [standalone]
Back to top | Article view | comp.os.linux.networking
csiph-web