Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Packet List Display

From: Sake Blok <sake@xxxxxxxxxx>
Date: Wed, 21 May 2008 17:16:47 +0200
On Wed, May 21, 2008 at 09:16:36AM -0400, Tony Fortunato wrote:
> Hi Everyone,
> 
> Just wondering if anyone has either figured out, or can tell me if its
> possible to change the Packet List Display to show IP as the displayed
> protocol.  
> 
> Just to clarify;
> - I wanted to see (and ideally export) the Packet List with the IP info as
> the displayed protocol, even if Wireshark can decode the higher protocols.

If I understand you correctly you want the Info column to display the
values as if IP was the last layer that was dissected by Wireshark?

I thought that would be possible to achieve by disabling all protocols
and then enabling only Ethenet and IP. But unfortunately the IP
dissector then just displays: "TCP (0x06)". 

When I disable the HTTP dissector, the Info Column will indeed show
the TCP info like there was no upper layer present.

Do you want the IP dissector to behave in the same manner? 
(ie showing IP details in the Info Column when the upper layer
protocol dissectors are disabled)

If so, could you file this as an enhancement request on
http://bugs.wireshark.org?

Cheers,
     Sake