This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I have a TCP session consisting of multiple packets. When I select any one of them and say "Decode as..." for my dissector, the dissector is properly applied to all packets in the entire session.

I can write a heuristic detector for my dissector that will match only the first packet in the sequence. However, when I do this, only the first packet is decoded by my dissector, and the remaining packets don't get dissected. Is it possible to tell the heuristic to apply the same dissector to all packets in the same TCP session?

asked 23 May '13, 07:53

LouisDx's gravatar image

LouisDx
11336
accept rate: 0%

edited 23 May '13, 07:53


once your heuristic kicks in you can set up a conversation and define your dissector as the conversation dissector. See conversation.h for the API and search the sources for examples (packet-sip, maybe).

permanent link

answered 23 May '13, 08:00

Anders's gravatar image

Anders ♦
4.6k952
accept rate: 17%

edited 23 May '13, 08:16

grahamb's gravatar image

grahamb ♦
19.8k330206

That sounds promising -- thanks!

(23 May '13, 08:06) LouisDx

It worked, perfect!

(23 May '13, 08:34) LouisDx
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×637
×10
×3
×3

question asked: 23 May '13, 07:53

question was seen: 1,455 times

last updated: 23 May '13, 08:34

p​o​w​e​r​e​d by O​S​Q​A