Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #1207 > unrolled thread

documentation for tcpdump

Started by"ghand" <ghand45@hotmail.com>
First post2012-03-25 08:32 +0100
Last post2012-03-25 10:00 +0100
Articles 3 — 2 participants

Back to article view | Back to comp.os.linux.networking


Contents

  documentation for tcpdump "ghand" <ghand45@hotmail.com> - 2012-03-25 08:32 +0100
    Re: documentation for tcpdump Ralph Spitzner <rasp@spitzner.org> - 2012-03-25 09:22 +0200
      Re: documentation for tcpdump "ghand" <ghand45@hotmail.com> - 2012-03-25 10:00 +0100

#1207 — documentation for tcpdump

From"ghand" <ghand45@hotmail.com>
Date2012-03-25 08:32 +0100
Subjectdocumentation for tcpdump
Message-ID<4f6ebc0b$1@x-privat.org>
I am a bit baffled re documentation for tcpdump.

I cannot figure out what the main source is.. I read that it is the man page..
But I just don't see things there that I do see elsewhere.

For example
This link http://www.tcpdump.org/#documentation
it says
"Full documentation is provided with the source packages in man page format.
People with Windows distributions are best to check the Windows PCAP page for
references to WinDUMP. What follows are the man pages formatted in HTML (using
man2html) and some tutorials written by external contributors."

So that suggests that it's all in the man page

Here is the man page
http://www.tcpdump.org/tcpdump_man.html

But in articles written by external contributors, I see many things not in
there.

e.g. This great article mentioned 
http://www.cs.ucr.edu/~marios/ethereal-tcpdump.pdf
Tcpdump filters, by Marios Iliofotou
says

there are three different kinds of qualifier.
type, dir, proto

When I go to the man page, I don't see the word "qualifier"

The man page does not mention the keyword   portrange
But it is mentioned here
http://www.msamir.net/the-art-of-network-debugging-with-tcpdump/

So where are the third party people getting the info from? 

Is the man page the main source and if so, where is the missing stuff? Is there
perhaps some other main documentation source by the tcpdump authors themselves?
 


 

[toc] | [next] | [standalone]


#1209

FromRalph Spitzner <rasp@spitzner.org>
Date2012-03-25 09:22 +0200
Message-ID<2nt249-4eg.ln1@spitzner.org>
In reply to#1207
ghand wrote:
> there are three different kinds of qualifier.
> type, dir, proto
>
> When I go to the man page, I don't see the word "qualifier"
>
> The man page does not mention the keyword   portrange
> But it is mentioned here
> http://www.msamir.net/the-art-of-network-debugging-with-tcpdump/

Are you referring to:

expression
               selects  which  packets  will  be dumped.  If
               no expression is given, all packets on the net will
               be dumped.
               Otherwise, only packets for which expression is `true'
               will be dumped.

               For the expression syntax, see pcap-filter(7).

???
	-rasp




-- 
See why I hate Windows users?
      All pain, no gain.
	-Howard Chu

[toc] | [prev] | [next] | [standalone]


#1210

From"ghand" <ghand45@hotmail.com>
Date2012-03-25 10:00 +0100
Message-ID<4f6ed0aa$1@x-privat.org>
In reply to#1209
Ralph Spitzner <rasp@spitzner.org> wrote:
>ghand wrote:
>> there are three different kinds of qualifier.
>> type, dir, proto
>>
>> When I go to the man page, I don't see the word "qualifier"
>>
>> The man page does not mention the keyword   portrange
>> But it is mentioned here
>> http://www.msamir.net/the-art-of-network-debugging-with-tcpdump/
>
>Are you referring to:
>
>expression
>               selects  which  packets  will  be dumped.  If
>               no expression is given, all packets on the net will
>               be dumped.
>               Otherwise, only packets for which expression is `true'
>               will be dumped.
>
>               For the expression syntax, see pcap-filter(7).
>
>???
>	-rasp
>
>

thanks, well spotted

[toc] | [prev] | [standalone]


Back to top | Article view | comp.os.linux.networking


csiph-web