Wireshark-users: Re: [Wireshark-users] [truncated] packets

From: andrew Wilson <a.wilson82@xxxxxxxxx>
Date: Mon, 15 Mar 2010 23:10:39 -0700

Thanks for the help.  Shortly after I wrote this I found that if you go to the packet itself and right-click on "copy all printable text" it will copy the whole request correctly to the clipboard.  I got the non-truncated information I needed that way.  :)


On Mon, Mar 15, 2010 at 11:05 PM, Guy Harris <guy@xxxxxxxxxxxx> wrote:

On Mar 15, 2010, at 10:21 PM, andrew Wilson wrote:

> I was recently reviewing a .pcap dump and I noticed that packet payloads with especially long lines are truncated.

Yes.  There is a limit of 240 characters for each line in the packet detail pane.

> I was looking for ideas how I can get this content out?  Is there a way to change the settings to not truncate or increase the size somehow?

You would have to change ITEM_LABEL_LENGTH in epan/proto.h in the Wireshark source code and recompile Wireshark.
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users

When I wrote this, only God and I understood what I was doing.  Now, God only knows - Karl Weierstrass