Wireshark mailing list archives

Re: Bit for starting / stopping / new Capture


From: Guy Harris <guy () alum mit edu>
Date: Wed, 17 Feb 2016 08:58:37 -0800



On Feb 17, 2016, at 7:16 AM, "FIXED-TERM Scholz Tobias (DC-IA/EAI)" <fixed-term.Tobias.Scholz () boschrexroth de > wrote:

I made some recherché, but couldn’t find any information to this topic. Is there a possibility to know (special bit for example), whe ther the user stopped, started the capture or opened Wireshark new?

There is nothing available to dissectors to indicate whether the packets are coming from a live capture or a capture done in the past, and thus there is nothing to indicate the status of a live capture.


That would be a great help for my dissector.

Why? What would you do differently, depending on whether you have a live capture and, if so, what the status of that capture is?
___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe

Current thread: