Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: Re: [Wireshark-dev] how does the wireshark print the contents of the packets

From: Jaap Keuter <jaap.keuter@xxxxxxxxx>
Date: Wed, 15 Sep 2010 13:13:24 +0200
Hi,

You'll find an interface between the wiretap library providing input
and the dissection engine in epan/packet.c:dissect_packet(). Here the
packet data is encapsulated in a TVB and presented to the top level
dissector.

Thanks,
Jaap

On Wed, 15 Sep 2010 15:17:51 +0800, 刘昆 <liukunmeister@xxxxxxxxx> wrote:
> If I want to understand how the wireshark print the contents of the
> packets wireshark just as the table at the bottom in wireshark GUI,which
> files should I read. In fact,I just want to find out the array which
> save the data of the packet wireshark has captured so that I can do some
> work with the data.As http protocol,should I read the files
> packet-http.c under the directory wireshark/epan/dissectors or other files?