Wireshark mailing list archives

Enrich tshark data


From: Conall Prendergast <conall.prendergast () anam com>
Date: Fri, 8 Sep 2017 14:21:19 +0100

Hi All,

Wireshark has the ability to enrich some of the numeric values it sees. For
example, if is sees a http status code of 200, it might print "OK" beside
it, because HTTP 200 means OK (This is just a guess, Im not sure what it
does for HTTP status codes).

Is it possible to add this kind of enrichment to tshark's json output?

Regards,
Conall

-- 


3 Custom House Plaza | IFSC | Dublin | D01 VY76 | Ireland | Tel.  +353 (1) 
291 0138 | Fax. +353 (1) 291 0131 

Asia Office - Suite 12.03, Level 12, Centrepoint North | Mid Valley City | 
59200 Kuala Lumpur | Malaysia | Tel. +603 2201 3375 

The information contained in this e-mail transmission is confidential and 
may be privileged. It is for the intended recipient only. Any views or 
opinions present are solely those of the author. If you are not the 
intended recipient you must not use, disclose, distribute, copy, print or 
rely on this e-mail. If you have received this e-mail in error, please 
immediately notify us by telephone at 353-1-2910138 or e-mail 
mailadmin () anam com and delete the email from your system
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe

Current thread: