Wireshark mailing list archives

Plugging decoder scripts into Wireshark


From: Mark Dawson <Mark.Dawson () imc-chicago com>
Date: Mon, 10 May 2010 15:23:14 -0500

We have protocols that we receive from various exchanges (e.g., NASDAQ, CME, etc.) that are encoded in different ways 
to transport market feeds to financial firms.

We capture this data for analysis with tcpdump and analyze it with Wireshark.  However, to decode the actual packet 
data, we have decoder tools we run against the it to get the actual market data (e.g., 300 shares of IBM sold@$85.32).

Do any of you know if it's possible to plug into Wireshark a decoder script, possibly written in Perl/Python/C, that 
will decode the packet data and display in a screen?  If we could do this, we can provide our decoder scripts to people 
not as technically savvy so they wouldn't have to tinker with our individual decoder scripts, but could just go through 
a familiar Wireshark screen and search through the data.

Is this possible?
________________________________
The information in this e-mail is intended only for the person or entity to which it is addressed.

It may contain confidential and /or privileged material. If someone other than the intended recipient should receive 
this e-mail, he / she shall not be entitled to read, disseminate, disclose or duplicate it.

If you receive this e-mail unintentionally, please inform us immediately by "reply" and then delete it from your 
system. Although this information has been compiled with great care, neither IMC Financial Markets & Asset Management 
nor any of its related entities shall accept any responsibility for any errors, omissions or other inaccuracies in this 
information or for the consequences thereof, nor shall it be bound in any way by the contents of this e-mail or its 
attachments. In the event of incomplete or incorrect transmission, please return the e-mail to the sender and 
permanently delete this message and any attachments.

Messages and attachments are scanned for all known viruses. Always scan attachments before opening them.
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

Current thread: