Wireshark-dev: [Wireshark-dev] Machine-readable dissector errors
From: "Thierry Emmanuel" <Emmanuel.Thierry@xxxxxxxxxxxxxxx>
Date: Tue, 1 Jun 2010 16:16:14 +0200

Hello,

 

I’m developing a probe designed to monitor bad and malformed packets on a network, so I plan to use epan as an independant library, without wireshark or tshark interface.

Here is the question : Is there a way to retrieve errors generated by dissectors under a more machine-readable representation ? I have seen this is possible for ip checksum thanks to the ip.checksum_good and ip.checksum_bad epan dissect tree elements, but what about other errors ?

 

Am I forced to parse each epan dissect tree element to seek for dissector generated errors ?

 

Best regards.

 

Emmanuel Thierry