Wireshark-users: Re: [Wireshark-users] Capture ss7 trace by Wireshark//Create custom columns

From: Jeff Morriss <jeff.morriss.ws@xxxxxxxxx>
Date: Wed, 13 Jan 2010 13:07:56 -0500
ahmed midany wrote:
Thanks a lot Jeff for your prompt reply but here are my comments:

Regarding the SS7oTDM Wireshark Capture setup, please see the reply from Utelsystems:

Unfortunately, we are no longer supporting WinPcap and Ethereal/Wireshark.

So, if you would like to use our E1/T1 PCMCIA card (or ExpressCard for newer notebook computers) for SS7 monitoring, you will also need our STINGA SS7 Monitor application.

Thanks for the info; I updated the Wiki page.

For the Custom Columns, the display filters helped me much but the only filter that i didn't find is the CIC:PCM/TS filter (in messages like Assignment Request/Block/BLA/UNBLO/UNBLA) :))) any ideas???

If you have such a message and can find the field you're looking for in the decode, clicking on it will tell you (in the status bar on the very bottom of the Wireshark window) the corresponding display filter. If not then you're probably out of luck.

(Looking at the GSM BSSMAP dissector, it appears that Assignment Request messages have a CIC but I don't see any timeslot fields--unless that information can somehow be derived from the CIC or some other field.)