This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

How do I query the 'info' field?

The following: info contains "mysql" produces error that it's not a field or protocol name. But 'info' is a field. It's the last field in the display on the right. I've tried uppercase and lowercase.

asked 03 Jun '16, 07:19

jtl's gravatar image

jtl
11113
accept rate: 0%


'info' is a column, therefore not a field. The term field is restricted to dissected parts of the frame, or generated thereof. Columns can be filled based on these fields, or from other sources. Therefore you cannot use a display filter on the info column.

permanent link

answered 03 Jun '16, 07:49

Jaap's gravatar image

Jaap ♦
11.7k16101
accept rate: 14%

On the other hand, the Info column can be queried using tshark and some external tools such as findstr or grep. As an example, see my answer to this question.

(03 Jun '16, 18:00) cmaynard ♦♦
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×349
×165

question asked: 03 Jun '16, 07:19

question was seen: 9,953 times

last updated: 03 Jun '16, 18:00

p​o​w​e​r​e​d by O​S​Q​A