ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-dev: [Wireshark-dev] PCAP to PDML Conversion

From: Rajeev Tomar <rajeev.tomar@xxxxxxxxxxx>
Date: Wed, 14 Jul 2010 20:09:30 +0530
Hi All
 
As of now I am just an end user of the Wireshark.
I am working on automating the log capturing the GSM Abis Message and then converting/ storing GSM Abis in XML format.
For more clarity
1. Start Wireshark
2. Convert PCAP to PDML
3. PDML to Automation XML format.
4. Stop Capturing
 
The PDML converted from PCAP
  • The conversion takes time in Step 2 and 3.
  • The converted pdml becomes very large in size
  • Much Information is redundant for me as field information stored as name/show name, value/unmasked value/display value.
  • Many Protocols are not needed to us.
 
To by knowledge the PCAP to PDML converter is built in feature of Wireshark, and as such independent of any dissector implemented.
It will be good if the modules which convert PCAP to PDML, can be modified so redundant field can be bypassed.
Please help me in identifying the module and guidance to do so.
 
Also is there any utility/api that traverse the protocol tree, so we can directly use that?
 
 
 
 
 
Regards
Rajeev Tomar
"Good, better, best; never let it rest till good is better and  better is best "
 

  ________________________________  
"DISCLAIMER: This message is proprietary to Aricent and is intended solely for the use of the individual to whom it is addressed. It may contain privileged or confidential information and should not be circulated or used for any purpose other than for what it is intended. If you have received this message in error, please notify the originator immediately. If you are not the intended recipient, you are notified that you are strictly prohibited from using, copying, altering, or disclosing the contents of this message. Aricent accepts no responsibility for loss or damage arising from the use of the information transmitted by this email including damage from virus."