Wireshark-users: [Wireshark-users] Display Filter troubleshooting

From: Hugo van der Kooij <hugo.van.der.kooij@xxxxx>
Date: Mon, 7 Dec 2015 10:05:47 +0000

Hi,

 

I am trying to find where I did goof up in creating a display macro.

 

I want to create a short cut for commands like:

((fw1.interface == "eth1") && ((fw1.direction == "i") || (fw1.direction == "O")))

 

So I got this in my display macro file now:

# This file is automatically generated, DO NOT MODIFY.

"fwmon_if","((fw1.interface == \x22$1\x22) && ((fw1.direction == \x22i\x22) || (fw1.direction == \x22O\x22)))"

"fwmon_rtr","((fw1.interface == \x22$1\x22) && ((fw1.direction == \x22I\x22) || (fw1.direction == \x22o\x22)))"

 

But it seems Wireshark is not willing to accept my macro.

I can’t use for example:

            $fwmon_if{eth1}

 

So I guess I am doing something horribly wrong but can’t figure out where I made the mistake.

 

Anyone willing to share some light on this?

 

Regards,

Hugo


Met vriendelijke groet / With kind regards,

Hugo van der Kooij
network engineer



Delft - Noord-Oost - Zuid


T: +31 15 888 0 345  F: +31 15 888 0 445
E: hugo.van.der.kooij@xxxxx  I:  www.qi.nl