Wireshark-users: Re: [Wireshark-users] Newbie Q - Displaying TCP data content in a column..

From: Kevin Hawkins <wireshark@xxxxxxxxxxx>
Date: Tue, 25 Nov 2008 12:09:10 +0000
I'd very much appreciate it if anyone could point me in the right direction with this - I know it's not a very exciting question but it would really help me resolve an problem I have.. and stepping through each packet one by one is very laborious.

  Chris
Apologies - I'm not very technical but I'm trying to display a new column that just shows the TCP data content of a conversation between two devices. The data is in plain ASCII.

I have setup filters for the IP's involved and if I select individual packess I can see the data in the hierarchical message dissection view below under the data heading. If I click on the latter part of that data in the hex/ascii pane it kindly highlights just the readable character portion of that data discarding what I assume is earlier binary header info. This highlighted text is exactly the info I want to see listed in a column against each packet , rather than having to examine each message individually - and even better to filter out all messages not containing such data. I'm sure this must be an easy one , and I've looked for a 'data' column type but there isn't one. Is there an easy way to do this ? Unfortunately I'm not upto writing any C or Lua code....

  Chris
_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
https://wireshark.org/mailman/listinfo/wireshark-users