This is our old Q&A Site. Please post any new questions and answers at

Hi, I'm writing some code that includes the parsing of SMB2 packets. Some packets have, say, three SMB2 apdus. If I use wireshark Apply as column the smb2.msg_id field I see all three msg_id values in the Packet List separated by commas. If I access the msg_id value in my LUA script I get the first msg_id in the packet only.

How can I access all the msg_id values?

Thanks and regards...Paul

asked 22 Aug '14, 15:28

PaulOfford's gravatar image

accept rate: 11%

Gerald Combs asked a similar question years ago on the Wireshark developers mailing list, and Tamás Regõs provided a response that you may find useful.

To quote:

In case the field occurrence is more than 1 then result of the will be a table/array and not just 1 value.

Try something like this:

    ip_src_f ="ip.src")
    local ip_src_table = { ip_src_f() }

    for i,ip_src in ipairs(p_src_table) do
        local src = tostring(ip_src.value)
        -- ....


permanent link

answered 26 Aug '14, 12:54

cmaynard's gravatar image

cmaynard ♦♦
accept rate: 20%

Thanks, that sounds promising. I'll give it a try and feedback the results.

Best regards...Paul

(29 Aug '14, 16:16) PaulOfford

Just tested this - it works a treat. Thanks for your help.

(01 Sep '14, 23:09) PaulOfford
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 22 Aug '14, 15:28

question was seen: 2,431 times

last updated: 01 Sep '14, 23:09

p​o​w​e​r​e​d by O​S​Q​A