hello i want a custom trigger set on a value changes from one value to another in same position in data to stop recording.. is it possible and if so how? thank you asked 26 Mar '15, 06:00 YaronS |
2 Answers:
If you are able to construct a capture filter for the value at the applicable field/offset location you are interested in, since you are using Windows and a new enough version of Wireshark, you may be able to make use of the In its simplest configuration to meet your needs, you would run it in "Dumcpap+Event" mode, specifying a general capture filter of packets you wish to capture along with an "Event" capture filter, which would be your very specific filter for the value at the offset you're looking for. Upon matching that specific filter, capturing would be terminated, optionally after some additional delay so that you could, if you wanted to, continue to capture some traffic for a specified time duration following the event of interest. The batch file can also configure For help with writing capture filters, refer to the pcap-filter man page. answered 26 Mar '15, 07:37 cmaynard ♦♦ Hello cmaynard thanks for the answer i will try to do that.. however when i run the dumpcap file i will choose option 5 to set the filter however i do not see any option for stopping the recording when i get wanted value with the filter.. as i never used the dumpcap file i appreciate some help.. thank you yaron (26 Mar '15, 08:06) YaronS As I explained, you will need to set the Dumpcap Mode to "Dumpcap+Event". This is option #2. Once you do that, you will see the (26 Mar '15, 08:11) cmaynard ♦♦ thank you now i see it.. i see there is also an option for trigger there.. maybe that will be good as well.. will try.. by the way where the file recorded being saved? thanks again Yaron (26 Mar '15, 08:24) YaronS 1 Trigger Mode is probably not what you want. In Trigger Mode, capturing isn't started UNTIL the event of interest occurs. Unfortunately, this means that the resulting capture file won't actually contain the packets leading up to the event, nor the event itself. Maybe this mode has some useful application, but none for me personally. (26 Mar '15, 08:28) cmaynard ♦♦ where the file recorded being saved? You specify the capture file and path in option #4, e.g.:
No need to add the .pcap or .pcapng extension as the batch file will auto-append the correct extension based on the format selected (option #9). If you don't specify a capture file, then
(26 Mar '15, 08:51) cmaynard ♦♦ |
There's nothing available really apart from parsing the output of tshark and then killing the capture process. answered 26 Mar '15, 06:52 grahamb ♦ hello grahamb thank you for the quick reply do you mean that i need to edit what the tshark is following on and when he sees it to kill the process? how do i edit the tshark output? with lua? or somthing else? Yaron (26 Mar '15, 07:05) YaronS |
Can you be a bit more specific about what you're trying to do? Also, what platform is this for, and what version of Wireshark are you using?
hello.. i wish to analyze a frame of data that being sent in a protocol (Profinet) and i want to catch the moment i have an error (that i can see when data changes to a certain value). Wireshark version 1.12.3, windows 7. i hope that is specified enough.. thanks