This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

payload description in info field

0

Hi -

My wireshark shows this information in the info field

http://www.jcitservices.plus.com/logs/Capture2.PNG

how can I get the information field to show this extra detail?

http://www.jcitservices.plus.com/logs/Capture1.PNG

Thanks in advance

asked 31 Oct '14, 00:50

wratty's gravatar image

wratty
16227
accept rate: 0%


One Answer:

1

how can I get the information field to show this extra detail?

By using a different verion of Wireshark. 1.12.x seems to only show the brief output, while 1.10.9 shows the extended output. Tested with the sample capture files linked in the UNISTIM wiki.

http://wiki.wireshark.org/UNISTIM

Regards
Kurt

answered 31 Oct '14, 01:38

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

edited 31 Oct '14, 02:44

Hi Kurt,

Thanks for the quick reply. I will try that.

(31 Oct '14, 02:12) wratty

fantascio!!

:D

(31 Oct '14, 02:18) wratty

Hmm the earliest I can find to download is 1.10.10 which as the same issue. Anyone know where I can get 1.10.9 from?

(31 Oct '14, 02:23) wratty

If you think there is a regression in 1.12.x open a bug report attaching a small capture to verify with.

(31 Oct '14, 02:26) Anders ♦

Then try it with 1.10.10 ;-)

(31 Oct '14, 02:43) Kurt Knochner ♦

Hi - I have tried with 1.10.10 and the same thing happens. limited info field population. I will open a bug case now, but i'm up against it with some system errors i am trying to debug.

(31 Oct '14, 03:47) wratty

maybe it's related to your capture file. Can you please try the following file with 1.10.10?

http://wiki.wireshark.org/SampleCaptures?action=AttachFile&do=view&target=unistim-call.pcap

(31 Oct '14, 04:23) Kurt Knochner ♦

I have tried 1.10.10 but the same issue applies.

(31 Oct '14, 05:17) wratty

The two screen captures used earlier in the opening post as using the same capture. One is on my wireshark, the other is the vendor on his wireshark, so the only difference is the version, or perhaps who he has his set up. No one seems to know of a setting to turn it on and I have tried to find if there is an "extended info" setting anywhere.

(31 Oct '14, 05:21) wratty

OK - I found the 1.10.9 version in the wireshark archive and it does the same for me, only limited info in the info window, I also tried using the test pcap file as suggestion above - so it is not the capture I have. so it must be a local setting.

ARGGGHHH help! :'-(

(31 Oct '14, 10:34) wratty

i've now tried 32b and 64b versions. still the same.

(01 Nov '14, 05:11) wratty

Perhaps the vendor has built an enhanced version and not submitted the code to wireshark...

(01 Nov '14, 05:41) Anders ♦

I don't think so as Kurt said up there...^^^ he tested it.

(01 Nov '14, 06:25) wratty

I just checked the source code of unistim plugin and the display of this extended info is not part of the official Wireshark (neither in 1.10.9 or in 1.12.1). It means that your vendor modified the source code to add it. BTW I do not see any different output between both versions when using the captured pointed by Kurt (which matches my analysis of the source code).

(01 Nov '14, 12:31) Pascal Quantin

OK thanks guys - I wish I knew how they done it.

(01 Nov '14, 15:46) wratty

I don't think so as Kurt said up there...^^^ he tested it.

Oops. Apparently I messed up two capture files :-( As @Pascal Quantin said, there is no difference between 1.10.x and 1.12.x.

Sorry for the confusion!

OK thanks guys - I wish I knew how they done it.

Ask them! As Wireshark is an open source project, it would violate the GPL to withhold those changes, as soon as they distribute the modified Wireshark version to their customers!

the other is the vendor on his wireshark,

Who is that vendor?

Regards
Kurt

(02 Nov '14, 04:15) Kurt Knochner ♦

I have asked the vendor if they have a special plugin/code for this

(03 Nov '14, 11:24) wratty

Who is the vendor?

(03 Nov '14, 12:05) Kurt Knochner ♦

Hi, ok it took me a while but they have given me this plugin...

http://www.jcitservices.plus.com/logs/unistim-120-v400-public.zip

I am yet to try it, as I am not on the correct PC at the mo.

(11 Nov '14, 01:30) wratty

Hmm. They should also be providing the sources for that binary as Wireshark is licenced under the GPL.

(11 Nov '14, 02:46) grahamb ♦

Again: Who is the vendor? :-))

(11 Nov '14, 14:35) Kurt Knochner ♦

The vendor is Avaya

(07 Dec '14, 04:53) wratty
showing 5 of 22 show 17 more comments