ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-users: Re: [Wireshark-users] How to extract the user-defined header data from the captu

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Fri, 6 Feb 2009 17:29:42 -0800

On Feb 6, 2009, at 3:20 PM, Abhik Sarkar wrote:

Hi Dinesh,

This is currently not possible, but I have submitted a patch
(https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3242) which might
make it possible.

Well, semi-possible, anyway. See the bug for details on why it doesn't work - and, if it adds additional header types when it sees them in the file, why it *can't* work - with TShark, and why it would be limited (for the same reason) in its use in Wireshark, and also see it for an alternative suggestion (which requires that the user explicitly tell Wireshark/TShark about those fields before it starts up).