Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: [Wireshark-dev] column format strings

From: Ed Beroset <beroset@xxxxxxxxxxxxxx>
Date: Tue, 15 Oct 2013 13:35:23 -0400 (GMT-04:00)
While attempting to answer a question[1] on ask.wireshark.org, I looked for the documentation for column format codes that may be used to customize tshark's output.  After a few minutes of searching, it seemed to me that the only place they're documented was in the source code, which seems rather user-unfriendly.  To fix this without adding a maintenance burden, I decided to add a "-G column-formats" option to tshark which prints all the format strings and descriptions using mostly existing code.  I also added a description of that glossary to the tshark.pod file.  Also, while I was in there, I noticed that several of the already existing glossary options (ftypes, heuristic-decodes and plugins) were missing from the documentation, so I've added those, too.  Bug is filed with patch.[2]


[1] http://ask.wireshark.org/questions/26001/show-untranslated-and-translated-mac-addresses-in-different-columns-at-the-time
[2] https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9272