I am attempting to generate a list of netbios names and IP addresses from WINS replies.
I would like to find a way to either create custom columns in wireshark and / or get the textual output using tshark. I have not been able to include a slice (IE:frame[55:33]) in a display filter. My Second Stumbling block is that windows encodes (MS calls it compression) the hostname in the reply.
Any assistance with this would be greatly appreciated.
asked 23 Sep '13, 16:56
edited 24 Sep '13, 20:06
Unfortunately, as per my comment, there's really no way to do that. I'll look at fixing that for the next major release; if the fixes aren't too complicated (I don't expect them to be too complicated), it might be worth backporting them to the 1.10 branch, so 1.10.3 or some other future 1.10.x release also lets you do that.
answered 24 Sep '13, 15:37
Guy Harris ♦♦
Wireshark supports columns for every field. Find the field you want to display in the protocol tree, right click it and then select "Apply as Column".
I haven't looked at WINS in Wireshark lately as we don't use it in our environment, but if you can't get Wireshark do do what you need, then Network Monitor from MS should handle it.
answered 24 Sep '13, 03:00