Wireshark-dev: Re: [Wireshark-dev] Trying to add computed value
From: "Hal Lander" <[email protected]>
Date: Sat, 02 Dec 2006 09:03:13 -0900
Thanks for the solution, I had the same problem.

Its probably a good idea to also put;
item=proto_tree_add_uint(my_tree, hf_my_item, tvb, offset, length, my_item_value);

That way Wireshark puts square brackets round the field to show it is calculated. If you select the field in the middle pane Wireshark will highlight in the lower pane the tvb contents defined by 'offset' and 'length' to show what raw data was used for the calculation.

From: Jaap Keuter <[email protected]>
Reply-To: Developer support list for Wireshark <[email protected]>
To: Developer support list for Wireshark <[email protected]>
Subject: Re: [Wireshark-dev] Trying to add computed value
Date: Mon, 27 Nov 2006 13:25:13 +0100 (CET)


Did you use something like this:

my_item_value = 2 * tvb_get_ntohs(tvb, offset);
proto_tree_add_uint(my_tree, hf_my_item, tvb, offset, 2, my_item_value);


On Mon, 27 Nov 2006 [email protected] wrote:

> Hiya
> I'm tring to get a calculated value to be displayed instead of the value
> pulled out of the packet. However all I get is the value in the packet.
> Can somebody tell an idiot what I need to do please!
> Cheers

Wireshark-dev mailing list
[email protected]
Get the latest Windows Live Messenger 8.1 Beta version. Join now. http://ideas.live.com