Hi, I am running wireshark version 1.10.6 on my ubuntu version. I am exporting IPFIX flows. However WLAN fields like, 365 staMacAddress 366 staIPv4Address 367 wtpMacAddress are not decoded in wireshark. Its reported as unknown. These fields are from IPFIX RFC 7012. Any help will be appreciated. Thanks SUNNY asked 06 Apr '15, 16:03 sunnycs |
One Answer:
These fields were implemented in development in the Wireshark netflow(ipfix) dissector in Sep 2014.. The added code was considered an "enhancement" and thus was not backported to Wireshark 1.10 or 1.12. So: (to be able to see these fields)
answered 06 Apr '15, 17:42 Bill Meier ♦♦ edited 06 Apr '15, 17:45 |