This is our old Q&A Site. Please post any new questions and answers at


I am using tshark version 2.0.2, and tshark is not able to decode the field gsm_a.imsi (SGSAP message).

Observing the below error message when I execute the tshark command.

tshark -r test.pcap -T fields -e gsm_a.imsi tshark: Some fields aren't valid: gsm_a.imsi

test.pcap has the sgsap message with imsi IE.

Anyone observing the same problem ? Can you please let me know how to resolve this issue. Thanks

asked 14 Apr '16, 12:26

srikanthtl's gravatar image

accept rate: 0%

That field was renamed to e212.imsi (this is actually a common IMSI field--so you can find all messages about a given IMSI, regardless of the protocol (at least for protocols that have been converted to use that field)).

permanent link

answered 14 Apr '16, 14:19

JeffMorriss's gravatar image

JeffMorriss ♦
accept rate: 27% works now

(14 Apr '16, 14:32) srikanthtl

(I converted your answer to a comment.)

If an answer answers your question, please be sure to accept it (by clicking on the checkmark next to the answer). That way the question will no longer show up as unanswered.

(14 Apr '16, 14:50) JeffMorriss ♦
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 14 Apr '16, 12:26

question was seen: 1,785 times

last updated: 14 Apr '16, 14:50

p​o​w​e​r​e​d by O​S​Q​A