Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: [Wireshark-dev] Problems with usb capture

From: Joerg Mayer <jmayer@xxxxxxxxx>
Date: Sun, 15 Oct 2006 00:09:35 +0200
Hello,

I've just updated my libcap to cvs head and managed to capture some
frames with wireshark/tshark. For some reason not clear to me, I get the
following message:

egg:~ # tshark -x -i usb4
Capturing on usb bus number 4
  0.000000               ->              UNKNOWN WTAP_ENCAP = 0

0000  00 00 00 04 00 00 00 01 00 00 00 01 00 00 00 00   ................
0010  0d 02                                             ..

  0.000000               ->              UNKNOWN WTAP_ENCAP = 0

0000  00 00 00 04 00 00 00 01 00 00 00 01 00 00 00 00   ................

  0.000000               ->              UNKNOWN WTAP_ENCAP = 0

0000  00 00 00 00 00 00 00 01 00 00 00 00 01 00 00 00   ................
0010  a3 00 00 00 00 01 00 04                           ........

  0.000000               ->              UNKNOWN WTAP_ENCAP = 0

0000  00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00   ................
0010  0d 01 01 01 00                                    .....

and so on and so on.

when I try to open the page from the sample captures:

jmayer@egg:~/work/wireshark/infos/usb> tshark -V -r mouse_replug2.pcap
tshark: The file "mouse_replug2.pcap" is a capture for a network type that TShark doesn't support.
(pcap: network type 186 unknown or unsupported)

Same problem.

Current svn head: Revision: 19531

Any ideas what is messed up?

thanks
     Joerg

PS: I've added some minimalistic infos on how to capture under linux.
-- 
Joerg Mayer                                           <jmayer@xxxxxxxxx>
We are stuck with technology when what we really want is just stuff that
works. Some say that should read Microsoft instead of technology.