[pcap-ng-format] Request: IDB:if_filter: add support for the "Wireshark Display Filter"
realrichardsharpe at gmail.com
Fri Jun 29 09:17:07 PDT 2012
On Fri, Jun 29, 2012 at 6:07 AM, Jose Pedro Oliveira <jpo at di.uminho.pt> wrote:
> This is a request for adding a new filter type - "Wireshark Display
> Filter"  - to the IDB:if_filter option.
> if_filter (option 11)
> Register a new filter type for the Wireshark's Display filter .
> More info:
> This would allow to store the display filter in contexts where
> they are used as (offline) capture filters.
> The content of the display filter would be a string (similar
> to the libpcap filter contents).
> * tshark offline filtering operation using the Wiretap API:
> tshark -R <display filter> -r in.pcapng -w out.pcapng
Thank you for your suggestion.
What are the advantages of this? Surely the filter can be stored as a
comment in the pcap-ng section header? (That is not to say that the
idea is not worth considering, just that it might need a good
In addition, moving forward, I don't think we are going to accept
requests for new fields, blocks, options, etc, unless they are
accompanied by patches to the reference implementation.
If you feel seriously enough about a change, then you should be
prepared to provide code to deal with that change.
More information about the pcap-ng-format