diff options
author | Ulf Lamping <ulf.lamping@web.de> | 2007-05-05 12:19:04 +0000 |
---|---|---|
committer | Ulf Lamping <ulf.lamping@web.de> | 2007-05-05 12:19:04 +0000 |
commit | e8900b8ee6c26f47fb6bd33598895b599dbeab59 (patch) | |
tree | fa1b5367cc4f0608907de8cecb89258302a6b409 /docbook | |
parent | 530b2735e923ee851946beb40641e2aa258bcd99 (diff) | |
download | wireshark-e8900b8ee6c26f47fb6bd33598895b599dbeab59.tar.gz |
-E path setting doc, update wireshark help output
svn path=/trunk/; revision=21692
Diffstat (limited to 'docbook')
-rw-r--r-- | docbook/wsug_src/WSUG_chapter_customize.xml | 97 |
1 files changed, 82 insertions, 15 deletions
diff --git a/docbook/wsug_src/WSUG_chapter_customize.xml b/docbook/wsug_src/WSUG_chapter_customize.xml index 24f26a1b1f..f7d86d3abe 100644 --- a/docbook/wsug_src/WSUG_chapter_customize.xml +++ b/docbook/wsug_src/WSUG_chapter_customize.xml @@ -50,24 +50,65 @@ <example id="ChCustEx1"> <title>Help information available from Wireshark</title> <programlisting> -Version 0.99.0 -Copyright 1998-2006 Gerald Combs <gerald@wireshark.org> and contributors. +Wireshark 0.99.6 +Interactively dump and analyze network traffic. +See http://www.wireshark.org for more information. -Compiled with GTK+ 2.6.9, with GLib 2.6.6, with WinPcap (version unknown), -with libz 1.2.3, with libpcre 6.4, with Net-SNMP 5.2.2, with ADNS, with Lua 5.1. +Copyright 1998-2007 Gerald Combs <gerald@wireshark.org> and contributors. +This is free software; see the source for copying conditions. There is NO +warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. -Running with WinPcap version 3.1 (packet.dll version 3, 1, 0, 27), based on -libpcap version 0.9[.x] on Windows XP Service Pack 2, build 2600. +Usage: wireshark [options] ... [ <infile> ] -wireshark [ -vh ] [ -DklLnpQS ] [ -a <capture autostop condition> ] ... - [ -b <capture ring buffer option> ] ... - [ -B <capture buffer size> ] - [ -c <capture packet count> ] [ -f <capture filter> ] - [ -g <packet number> ] [ -i <capture interface> ] [ -m <font> ] - [ -N <name resolving flags> ] [ -o <preference/recent setting> ] ... - [ -r <infile> ] [ -R <read (display) filter> ] [ -s <capture snaplen> ] - [ -t <time stamp format> ] [ -w <savefile> ] [ -y <capture link type> ] - [ -X <eXtension option> ] [ -z <statistics> ] [ <infile> ] </programlisting> +Capture interface: + -i <interface> name or idx of interface (def: first non-loopback) + -f <capture filter> packet filter in libpcap filter syntax + -s <snaplen> packet snapshot length (def: 65535) + -p don't capture in promiscuous mode + -k start capturing immediately (def: do nothing) + -Q quit Wireshark after capturing + -S update packet display when new packets are captured + -l turn on automatic scrolling while -S is in use + -B <buffer size> size of kernel buffer (def: 1MB) + -y <link type> link layer type (def: first appropriate) + -D print list of interfaces and exit + -L print list of link-layer types of iface and exit + +Capture stop conditions: + -c <packet count> stop after n packets (def: infinite) + -a <autostop cond.> ... duration:NUM - stop after NUM seconds + filesize:NUM - stop this file after NUM KB + files:NUM - stop after NUM files +Capture output: + -b <ringbuffer opt.> ... duration:NUM - switch to next file after NUM secs + filesize:NUM - switch to next file after NUM KB + files:NUM - ringbuffer: replace after NUM files +Input file: + -r <infile> set the filename to read from (no pipes or stdin!) + +Processing: + -R <read filter> packet filter in Wireshark display filter syntax + -n disable all name resolutions (def: all enabled) + -N <name resolve flags> enable specific name resolution(s): "mntC" + +User interface: + -g <packet number> go to specified packet number after "-r" + -m <font> set the font name used for most text + -t ad|a|r|d|dd|e output format of time stamps (def: r: rel. to first) + -X <key>:<value> eXtension options, see man page for details + -z <statistics> show various statistics, see man page for details + +Output: + -w <outfile|-> set the output filename (or '-' for stdout) + +Miscellaneous: + -h display this help and exit + -v display version info and exit + -P <key:path> persconf:path - personal configuration files + persdata:path - personal data files + -o <name>:<value> ... override preference or recent setting + +</programlisting> </example> We will examine each of the command line options in turn. @@ -354,6 +395,32 @@ standard libpcap format. </para> </listitem> </varlistentry> + <varlistentry><term><command>-P <path setting></command></term> + <listitem> + <para> + Special path settings usually detected automatically. This is used + for special cases, e.g. starting Wireshark from a known location on + an USB stick. + </para> + <para> + The criterion is of the form key:path, where key is one of: + <variablelist> + <varlistentry><term><command>persconf</command>:path</term> + <listitem><para> + path of personal configuration files, like the preferences files. + </para></listitem> + </varlistentry> + <varlistentry><term><command>persdata</command>:path</term> + <listitem><para> + path of personal data files, it's the folder initially opened. + After the initilization, the recent file will keep the folder + last used. + </para></listitem> + </varlistentry> + </variablelist> + </para> + </listitem> + </varlistentry> <varlistentry><term><command>-Q</command></term> <listitem> <para> |