Ask Your Question

Documentation/Use of new protobuf dissector

asked 2018-05-02 21:41:52 +0000

ahaywood gravatar image

In the release notes for 2.6.0 it indicates a new dissector has been added to wireshark for protobuf.

However, there is no mention of it in either the user or developer documentation.

I have a couple questions:

  1. How to provide the .proto file?
  2. It looks like it doesn't detect fields that contain other fields, and only detects the top level fields. Am I using it wrong?


edit retag flag offensive close merge delete


I would also really like to be able to have a preference where I could e.g. map from UDP port -> .proto file (where presumably the last/root Message type from the file is what would be used). The last comment from last month here gives me hope that Huang Qiangxiong will put up something for review soon.

The 2 issues appear to be related - I don't think you can reliably dissect into embedded messages without knowing the types from the .proto files.

MartinM gravatar imageMartinM ( 2018-05-03 08:42:06 +0000 )edit

2 Answers

Sort by ยป oldest newest most voted

answered 2020-03-14 11:59:22 +0000

Skison gravatar image

updated 2020-03-14 11:59:59 +0000

edit flag offensive delete link more

answered 2018-05-02 22:02:40 +0000

Jaap gravatar image

From the source code:

  Support custom preference settings for embedded messages.
  Dissect message according to '*.proto' files.
edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2018-05-02 21:41:52 +0000

Seen: 1,208 times

Last updated: Mar 14 '20