Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: Re: [Wireshark-dev] How to add a wtap encapsulation?

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Thu, 14 Oct 2010 10:59:29 -0700
On Oct 13, 2010, at 8:48 AM, Yo Mismo wrote:

> I haven't got #define WTAP_ENCAP_IEEE802_15_4_NOFCS                127 in wtap.h :(

You probably have an older version of Wireshark.

> I have been reading pcap-common.c, I haven't asked for a new DLT_ value because my dissector and the encapsulation are for academic purpose only and wont be used in future.

Then, if your captures are in pcap format, you should use one of the DLT_USERn values in the file, and use the corresponding WTAP_ENCAP_USERn encapsulation value in your dissector.