Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] wireshark 1.6+: pcapng NBR blocks

From: Anders Broman <a.broman@xxxxxxxxxxxx>
Date: Wed, 07 Dec 2011 07:34:49 +0100
Jose Pedro Oliveira skrev 2011-12-06 18:24:
Hi,

According to the Wireshark 1.6 release notes [1], tshark is able
to read and write host name information from and to pcapng, but I
can't figure out how to make tshark create NBR blocks during, or at
the end, of a capture.

A pcapng file created with tshark 1.7.1svn only seems to have
SHB, IDB, EPB and ISB blocks.

Could someone give me a hint?
For what it's worth this is the code changes that added the functionality
http://anonsvn.wireshark.org/viewvc/trunk/tshark.c?r1=36077&r2=36318


tia,
jpo

[1] - https://www.wireshark.org/docs/relnotes/wireshark-1.6.0.html