Wireshark-users: Re: [Wireshark-users] How to display identical fields with tshark

From: Martin Visser <martinvisser99@xxxxxxxxx>
Date: Fri, 7 Jan 2011 13:38:04 +1100
PDML is a just an XML format of the packet dissection. I don't know of
anything formal - I have previously just parsed it using some pretty
basic Perl or Python

Regards, Martin

MartinVisser99@xxxxxxxxx



On 7 January 2011 06:59, eymanm <eymanm@xxxxxxxxx> wrote:
> Martin,
> Can you elaborate a bit on the PDML approach. Is there a mechanism within
> WireShark to deal with the PDML? Or the XSLT is the way to go? Can you point
> to any documentation?
> Thanks
> On Wed, Jan 5, 2011 at 6:11 PM, Martin Visser <martinvisser99@xxxxxxxxx>
> wrote:
>>
>> Also as an interim measure, you may want to make use of the PDML
>> output instead (which will show all fields). This will require
>> separate parsing of course to be useful.
>>
>> Regards, Martin
>>
>> MartinVisser99@xxxxxxxxx
>>
>>
>
> ___________________________________________________________________________
> Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
> Archives:    http://www.wireshark.org/lists/wireshark-users
> Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
>             mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe
>