Wireshark-users: [Wireshark-users] Tshark Tcap filtering
From: Erdinç Taşkın <erdinctaskin@xxxxxxxxx>
Date: Tue, 20 Sep 2011 15:32:18 +0300
Hello,

I have a problem about filtering from pcap file. I got a capture file that created by tcpdump. I use filter criteria that "(tcap.tid == 01:5e:00:00) || (tcap.tid == 53:d0:90:96)" on wireshark found packet. On same capture file, using tshark (exact command "/tshark -R "(tcap.tid == 01:5e:00:00) || (tcap.tid == 53:d0:90:96)" -r test.pcap") does not match any packet. What is wrong? 

Thanks for helps