This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Noticed a change in how EBCDIC information is presented from /030 to no longer do that.

0

I was using the 1.4.4 release of Wireshark and upgraded to the 1.6 release and noticed that for MQ traffic that is talking between Unix and zOS systems the characters are now hidden instead of being shown as octocl information such as (slash) 343 (slash) 342 (slash) 310 type of information.

I was able to use that for other post processing to actually see traffic interactions bewteen these systems. This was by using the results from the tags like Remote Queue: and notice the 347 type of marking and then translate that to a character. Now I no longer have the option to do that.

I have had to bad level my wireshark to keep this function. Yet I like the newer features in 1.6 except for that one feature. Could it be an option to use the Octocl or the marker?

asked 29 Jun '11, 05:03

hsteinhauer's gravatar image

hsteinhauer
1112
accept rate: 0%

edited 29 Jun '11, 05:05


2 Answers:

0

This sounds like a bug report to me. Please file it here, with a sample capture file for the developers to work/test with.

answered 29 Jun '11, 06:55

Jaap's gravatar image

Jaap ♦
11.7k16101
accept rate: 14%

OK - -I opened up a bug report

(01 Jul '11, 19:01) hsteinhauer

0

OK, the MQ dissector in the SVN trunk translates EBCDIC strings to ASCII before showing them in the Info column or packet details. That's scheduled for backporting to 1.6.1.

answered 03 Jul '11, 14:41

Guy%20Harris's gravatar image

Guy Harris ♦♦
17.4k335196
accept rate: 19%