This is our old Q&A Site. Please post any new questions and answers at

Hi all, is it possible to set up a capture filter in wireshark for the decode as feature just like tshark -d option i.e. -d udp.port==8000,rudp, before to start capture ?

This question is marked "community wiki".

asked 08 Apr '11, 06:59

flap78's gravatar image

accept rate: 0%

You could do that using lua

In your c:program filesWireshark directory find init.lua file.

Comment out disable_lua line and at the end of the file add dofile("decodes.lua"). Then create a file in the same directory called decodes.lua

Edit it to have contents like below

    local rudp_dissector=Dissector.get("rudp")
    local udp_table=DissectorTable.get("udp.port")
    udp_table:add(8000, rudp_dissector)

Now each time you start wireshark traffic on 8000 port will be decoded as rudp

Instead of having it as permanent solution you can use command line option -Xlua_script:./decodes.lua when starting wireshark.

permanent link

answered 11 Apr '11, 09:01

izopizo's gravatar image

accept rate: 0%

Currently this is not possible, but there has been interest in having this feature available. See bugs 2931 and 5143 in particular. Perhaps someone will implement this one day.

permanent link

answered 11 Apr '11, 07:49

cmaynard's gravatar image

cmaynard ♦♦
accept rate: 20%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 08 Apr '11, 06:59

question was seen: 5,037 times

last updated: 11 Apr '11, 09:01

p​o​w​e​r​e​d by O​S​Q​A