Ask Your Question

Splitting Syslog dissector message columns

asked 2018-07-17 09:12:51 +0000

MSK gravatar image


I would like to split the message part of the syslog dissector so that they are displayed in columns as the syslog message we have is pretty long and is not easy to read. I was wondering what would be the best possible way ? I am looking for ways to not make any changes to the syslog source file as this may interfere when we update the wireshark source.

Any suggestions is highly appreciated.

Best Regards,

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted

answered 2018-07-17 14:00:13 +0000

cmaynard gravatar image

I don't think you can split the syslog message.

You can right-click on the syslog.msg field and choose, "Apply as Column", but I don't think that's going to help you.

You could try using tshark instead, perhaps with something like this:

tshark -r file.pcap -T fields -e frame.number -e syslog.msg
edit flag offensive delete link more


Thanks for the reply. I can split the actual syslog message to display as columns the facility, level, and the Message (which contains actual specific information about our packets). I am trying to find a way to split the our Message without changing the code in packet-syslog.c.

MSK gravatar imageMSK ( 2018-07-18 00:51:24 +0000 )edit

Maybe if you provide an example of your message and how you would like it to be split up, then someone might be able to help you come up with a script that could process the tshark syslog.msg field and split it up according to your criteria. You won't be able to split it up with Wireshark.

cmaynard gravatar imagecmaynard ( 2018-07-18 15:31:11 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2018-07-17 09:12:51 +0000

Seen: 458 times

Last updated: Jul 17 '18