why can I see the mqtt traffic only in the info column? (same for http)

Hello, I am writting my thesis and I connected a Raspberry Pi via Hotspot to my laptop.

I want to caputre the mqtt traffic for the Raspberry Pi. It works but I only can see the MQTT traffic in the info column. Why is it no own Protocol in the protocol column?

I would really appreciate it, if someone can help me.

Best regards

What ports is your traffic running on, and what ports have you configured in wireshark for MQTT and HTTP?

Can you share a capture file with a public link, e.g. CloudShark, Google Drive, DropBox etc?

grahamb gravatar imagegrahamb ( 2018-03-06 12:24:20 +0000 )edit

I am completely new in wireshark.

This ist the link for the captured traffic. In the info column is mqtt but I want it in the protocol column. I don't know where I can fix the right filter. And the mqtt port is 8883.

Thank you for the fast answer.

Mari1234 gravatar imageMari1234 ( 2018-03-06 12:32:53 +0000 )edit

It looks like your running MQTT encrypted inside TLS (SSL). I guess the TLS Application data (e.g. frame 145) contains your MQTT messages. However only encrypted.

=> To be able to see the MQTT payload you have to be able to decrypt the TLS session (e.g. by having the session key or the RSA key).

