TSHARK Field Extraction

For those of you who don’t know what TSHARK is you are missing out on a very powerful program.  TSHARK is essentially a command line version of wireshark.  Now, why is this important?  Well when dealing with very large PCAP files, wireshark tends to choke on the file processing.  Well, enter TSHARK.  It has the ability to quickly go through…