SIP Custom field data.text blank or just "Yes"
Hi,
I have been testing SIP client/server, where I am just sending Instant messages on a local Lan between sip clients... I'm using Wireshark version (2.4.1) on windows 10...And as far I can tell everything works fine all the data I need is captured accordingly...
However I'm new to Wireshark and desperately need to work this out...I want to see at a glance the actual body of the message in a column?
In earlier versions people (i.e https://osqa-ask.wireshark.org/questi... ) have worked out how to display the "data.text" an therefore see the actually message of the Message body in a Custom column field... When I try this , it either shows up blank or just a single word "yes",
If I click a row from this custom column, where it has marked in the field "yes" , clearly down below I can see in plain text, which the user/client has typed...i.e the Message Body
Session Initiation Protocol ->Message Body->Line-Based text data: text/plain ....some information someone sent as an instant message over sip...etc
I have gone to preferences->Protocol->Data->show data as text (is selected)
why does this not work, I can't see why not...Please help
thank you :-)
Can you publish an example capture file at cloudshark or at any plain file sharing service and edit your Question with a login-free link to it?
But in general,
data
(anddata.text
if configured so) are only added to the protocol dissection tree when part of the frame cannot be dissected better than that. So I can imagine that in the meantime between that osqa-ask post and now, dissection of SIP IM body has been added, so you now need to add, as a packet list column, some other field thandata.text
. Or, if you don't like the way that field is displayed, it may be possible to switch off the dissection of SIP IM body, which would mean that it would again be shown as justdata
.Hi and thanks, I have located a field in the detail pane called "Session Initiation Protocol (MESSAGE)", which has sub fields Request-Line, Message Header and Message Body... inside Message Body, sub fields "Line-Based text data: text/plain" with the actual IM text following it...
However Applying as Column, Message Body or any of it's subfields produces the same blank column field..so what am I doing wrong?
Note I do not have this problem with Request-Line or Message Header and any of their sub fields...just problems with Message Body and its subfields....
You'd have to publish a capture file (it is sufficient if there is just a single packet which does contain the message text inside) to possibly get an explanation. To create a file like this, open your capture in Wireshark, select a packet meeting the requirement in the packet list, go
File -> Export Selected Packets
and check theSelected packet
checkmark. Then specify a file name and pressSave
. Next, publish that file at Cloudshark or any plain file sharing service and edit your Question with a login-free link to it. If the SIP transport is TCP, this may not be sufficient so in such case, better check by opening the file before uploading it.