This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I am building a plugin for Wireshark, and I have several global variables that record and keep track of data from different packets. When a new capture is opened, I want to be able to clear these variables so the previous data isn't mixed up with the new data.

Is there a function or property in Wireshark that can alert me that a new capture file has been opened?

asked 22 Aug '14, 18:22

Frankie's gravatar image

Frankie
31115
accept rate: 0%


You can register a callback function thanks to the register_init_routine() function that will be called when opening a new capture (or applying a display filter). In your function, clear your data. You can see an example in packet-tcp.c.

permanent link

answered 23 Aug '14, 03:32

Pascal%20Quantin's gravatar image

Pascal Quantin
5.5k1060
accept rate: 30%

Worked perfectly, thanks!

(25 Aug '14, 16:04) Frankie
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×1,620
×173
×37

question asked: 22 Aug '14, 18:22

question was seen: 1,419 times

last updated: 25 Aug '14, 16:04

p​o​w​e​r​e​d by O​S​Q​A