Wireshark-users: Re: [Wireshark-users] Tshark statistics problem
From: "Jo Verstraelen" <J.Verstraelen@xxxxxxxxxx>
Date: Fri, 3 Apr 2009 16:16:37 +0200

Sake,

 

Thanks for the input

And indeed putting my regional settings to English (us) did fix the problem.

So is there a way to do this without changing settings?

 

 

 

Kind regards,

                    Jo

 

Ps. This should be documented in the tshark manual…


From: wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Sake Blok
Sent: Friday, April 03, 2009 2:43 PM
To: Community support list for Wireshark
Subject: Re: [Wireshark-users] Tshark statistics problem

 

Jo,

 

Have a look at your regional settings and make sure the "," is not your decimal seperator :-)

 

Hope this helps,

Cheers,

     Sake

----- Original Message -----

Sent: Friday, April 03, 2009 11:23 AM

Subject: [Wireshark-users] Tshark statistics problem

 

Hi,

 

Does some one know why the following command: “Tshark.exe –r testfile.pcap –q –z io,stat,30,COUNT(tcp.analysis.retransmission) tcp.analysis.retransmission” outputs this:

 

C:\Program Files\Wireshark>tshark.exe -r update.pcap -q -z io,stat,30,COUNT(tcp.

analysis.retransmission)cp.analysis.retransmission

 

===================================================================

IO Statistics

Interval: 30.000 secs

Column #0:

                |   Column #0

Time            |frames|  bytes

000.000-030.000       2       444

030.000-060.000       1       222

060.000-090.000       1       222

090.000-120.000      17      3081

120.000-150.000   23676  22054026

150.000-180.000   39681  37077760

180.000-210.000   88041  83327179

210.000-240.000   86237  81549459

240.000-270.000   43381  40256634

270.000-300.000    8147   7507780

300.000-330.000       2       472

330.000-360.000       3       348

360.000-390.000       1       222

390.000-420.000       1       222

420.000-450.000       2       314

450.000-480.000     163     47626

 

Instead of a column with the counted tcp retransmissions?

 

Got the same result with :

tshark.exe –r testfile.pcap” –q –z io,stat,30,”COUNT(tcp.analysis.retranmission)tcp.analysis.retransmission”,”AVG(tcp.window_size)tcp.window_size”,”MAX(tcp.window_size)”,”MIN(tcp.window_size)tcp.window_size”


I am using TShark 1.1.3 (SVN Rev 27807) .

(testfile.pcap does contain tcp and retransmission so its not that)

 

Kind regards,

                    Jo


___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe