frame.number >= 5frame.time>="Oct 1, 2010 10:30:20"tshark -r input.pcap -Y "ip.addr==192.168.1.1 && tcp.port=8080" -w output.pcap
tcpdump を使う場合は
tcpdump -r input.pcap "tcp and host 192.168.1.1 and port 8080" -w output.pcap
tshark -r input.pcap -Y "tcp.flags.reset==1" -w output.pcap
他には tcp.flags.syn, tcp.flags.ack など。
editcap -A "2025-01-01 09:00:00" -B "2025-01-01 09:10:15" input.pcap output.pcap
または tshark を使用
tshark -r input.pcap -Y "frame.time >= \"2025-01-10 09:00:00\" && frame.time <= \"2025-01-01 09:10:15\"" -w output.pcap
sudo chown $(whoami):admin /dev/bpf*