Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Betr: custom columns?

From: "Marlon Duksa" <mduksa@xxxxxxxxx>
Date: Tue, 12 Aug 2008 09:46:52 -0700
Hi Joan - this is good and it solves my problem partially. It looks like that if I do it this way, and if I have repeating headers in my frames, that the filter will always pick up the last one (the deepest header in the frame). Do you know if I can specify which header I want to filter on?

For example, I have three etherent headers encapsulated in my packet. How do I tell it to filter on the second ethernet header and  and not on the third one, which is the default mode of operation for the approach you suggested. Thanks,
Marlon

On Mon, Aug 11, 2008 at 11:58 PM, <j.snelders@xxxxxxxxxx> wrote:
Hi Marlon,

To create Costum columns go to:
Edit > Preferences > Columns

Select: New
Title: <your choice>
Format: select Custom
Field (no title): display filter

The display filters are (http://www.wireshark.org/docs/dfref/):
eth.src
eth.dst
mpls.label

HTH
Joan

>-- Oorspronkelijk bericht --
>Date: Mon, 11 Aug 2008 11:09:38 -0700
>From: "Marlon Duksa" <mduksa@xxxxxxxxx>
>To: wireshark-users@xxxxxxxxxxxxx
>Subject: [Wireshark-users] custom columns?
>Reply-To: Community support list for Wireshark <wireshark-users@xxxxxxxxxxxxx>
>
>
>Does anyone know how can I display certain fields of my capture in the
>column field of the Wireshark window.
>My each captured frame consist of 3 Etherent headers and two MPLS headers
>and I'd like to diplay only hw src/dst fields from the second Etherent
>header and also the MPLS label from the second MPLS header in colum fields
>at the top of Wireshark window. In addition to what is already diplayed
in
>the colums filed (timestamp, pkt #, src, dst IP, info...) Please see
>captured jpeg for the fileds that I'd like to display.
>
>In the Wireshark:preferences->User Interfaces -> columns I did see some
>custom format field but no help on how to use it.
>
>Thanks,
>Marlon
>
>Bijlage: wireshark.JPG
>
>_______________________________________________
>Wireshark-users mailing list
>Wireshark-users@xxxxxxxxxxxxx
>https://wireshark.org/mailman/listinfo/wireshark-users





_______________________________________________
Wireshark-users mailing list
Wireshark-users@xxxxxxxxxxxxx
https://wireshark.org/mailman/listinfo/wireshark-users