Wireshark-users: Re: [Wireshark-users] Print wireshark option from command
From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Tue, 16 Dec 2008 00:46:09 -0800
On Dec 16, 2008, at 12:37 AM, Stephen Fisher wrote:

You need to use -Tfields instead of -Ttext
Is there a way to get the value of the protocol column with "-T  
fields" and "-e"?  Everything else is a field (although he might want  
the generic source and destination addresses if he has any non-IPv4  
traffic), but the column values aren't necessarily registered fields.