Updating MATE config

asked 2018-08-08 03:08:40 +0000

Scott Harman gravatar image

updated 2018-08-08 03:09:53 +0000

Hi team - I'm trying to work out what's changed in Wireshark between version 2 and 2.6 with regard to MATE

Previously I was successfully matching sessions and PDUs based on the following - but now a new PDU is being created for every message

Pdu giop_pdu Proto giop Transport tcp/ip {
    Extract giop_addr From ip.addr;
    Extract giop_port From tcp.port;
    Extract giop_type From giop.type;
    Extract giop_request_id From giop.request_id;
    Extract giop_request_op From giop.request_op;

Gop giop_req On giop_pdu Match (giop_addr, giop_addr, giop_port, giop_port,giop_request_id) {
        Start (giop_type = 0);
        Stop (giop_type = 1);
        Extra (giop_request_op);

Gog giop_session {
    Member giop_req(giop_addr, giop_addr, giop_port, giop_port,giop_request_id );
    Extra (giop_request_op);

Now, I'm getting the PDU displayed, but I'm not able to filter on the request/reply Capture example

https://i.imgur.com/XVR06dR.png (image linked separately so it's easier to view)

I'm sure I'm missing something obvious, but I can't work out the syntax to ensure that I'm matching the right object in the reply

edit retag flag offensive close merge delete