This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I am using tshark with matlab so that we can analyze the data in matlab. I recently had a problem where a UDP "blob" message was being decoded as an GVSP message, and in some instances the Field "data" was not being returned in the tshark decode. I eventually discovered that if I turned off the GVSP protocol in wireshark that the tshark decoding then worked.

Since I deliver the matlab that calls the tshark to "clients", it would be nice if I didn't have to also tell them to disable GVSP. I also deliver this to clients on both Linux and windows who may have totally different versions of wire shark installed, so to build a configuration that has GVSP disabled would be problematic.

So to get to the question is there a way that I can just define on the command line that I want all UDP messages to be decoded as UDP and nothing else?

Thanks Mark

asked 31 Jan '17, 06:13

petschek's gravatar image

petschek
6112
accept rate: 0%


From the tshark man page:

--disable-protocol <proto_name>

    Disable dissection of proto_name.

If the version of Wireshark is too old and doesn't support this option, you could add gvsp to the disabled_protos file located in the Wireshark "Personal configuration" folder.

But since that changes the users' configuration, perhaps a better alternative is for you to create a separate "matlab" Wireshark profile and ask your users to copy it to their "Personal configuration" profiles directory, which would only need to be done once. That profile could disable all protocols except for only those that you want enabled. After that, you can just run tshark with the [ -C configuration profile ] option. All other profiles would be unaffected.

permanent link

answered 31 Jan '17, 07:50

cmaynard's gravatar image

cmaynard ♦♦
9.3k1038142
accept rate: 20%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×832
×166
×89

question asked: 31 Jan '17, 06:13

question was seen: 2,204 times

last updated: 31 Jan '17, 07:50

p​o​w​e​r​e​d by O​S​Q​A