Hi, I have been using Wireshark a lot recently, and something that would be useful is: Being able to add a new column and linking a field, like smb.fid, to it. This would allow me to sort on fields like FID and easily see which FIDs are missing in a capture, and so forth. How hard would that be to do? -- Regards, Richard Sharpe