Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

Decode as... doesn't work, what am I missing?

I'm doing a capture with SSH remote capture, which all works fine - normally. I'm trying to decode HTTP traffic on a non-standard port.

So I've clicked on the TCP row, gone to Decode As... and added the destination service port as the TCP Port number to match, and set the Current value to HTTP, then saved. Nothing changes.

I've tried on another computer, with a new install of Wireshark, I've blown away my local preferences, no avail. I feel like I'm doing something really, really dumb here, but it's simply not working.

Decode as... doesn't work, what am I missing?

I'm doing a capture with SSH remote capture, which all works fine - normally. I'm trying to decode HTTP traffic on a non-standard port.

So I've clicked on the TCP row, gone to Decode As... and added the destination service port as the TCP Port number to match, and set the Current value to HTTP, then saved. Nothing changes.

I've tried on another computer, with a new install of Wireshark, I've blown away my local preferences, no avail. I feel like I'm doing something really, really dumb here, but it's simply not working.

Version 4.4.6 (v4.4.6-0-gaebb20483889).

Compiled (64-bit) using Microsoft Visual Studio 2022 (VC++ 14.41, build 34123),
with GLib 2.80.0, with Qt 6.5.3, with libpcap, with zlib 1.3.1, with zlib-ng
2.1.5, with PCRE2, with Lua 5.4.6 (with UfW patches), with GnuTLS 3.8.4 and PKCS
#11 support, with Gcrypt 1.10.2-unknown, with Kerberos (MIT), with MaxMind, with
nghttp2 1.62.1, with nghttp3 0.14.0, with brotli, with LZ4, with Zstandard, with
Snappy, with libxml2 2.13.5, with libsmi 0.5.0, with Minizip-ng , with
QtMultimedia, with automatic updates using WinSparkle 0.8.0, with AirPcap, with
binary plugins.

Running on 64-bit Windows 11 (24H2), build 26100, with AMD Ryzen 9 9950X3D
16-Core Processor (with SSE4.2), with 65175 MB of physical memory, with GLib
2.80.0, with Qt 6.5.3, with Npcap version 1.79, based on libpcap version 1.10.4,
with PCRE2 10.43 2024-02-16, with c-ares 1.27.0, with GnuTLS 3.8.4, with Gcrypt
1.10.2-unknown, with nghttp2 1.62.1, with nghttp3 0.14.0, with brotli 1.0.9,
with LZ4 1.9.4, with Zstandard 1.5.6, without AirPcap, with dark display mode,
without HiDPI, with QPA plugin "windows", with LC_TYPE=English_United
Kingdom.utf8, binary plugins supported.

Decode as... doesn't work, what am I missing?

I'm doing a capture with SSH remote capture, which all works fine - normally. I'm trying to decode HTTP traffic on a non-standard port.

So I've clicked on the TCP row, gone to Decode As... and added the destination service port as the TCP Port number to match, and set the Current value to HTTP, then saved. Nothing changes.

I've tried on another computer, with a new install of Wireshark, I've blown away my local preferences, no avail. I feel like I'm doing something really, really dumb here, but it's simply not working.

Version 4.4.6 (v4.4.6-0-gaebb20483889).

Compiled (64-bit) using Microsoft Visual Studio 2022 (VC++ 14.41, build 34123),
with GLib 2.80.0, with Qt 6.5.3, with libpcap, with zlib 1.3.1, with zlib-ng
2.1.5, with PCRE2, with Lua 5.4.6 (with UfW patches), with GnuTLS 3.8.4 and PKCS
#11 support, with Gcrypt 1.10.2-unknown, with Kerberos (MIT), with MaxMind, with
nghttp2 1.62.1, with nghttp3 0.14.0, with brotli, with LZ4, with Zstandard, with
Snappy, with libxml2 2.13.5, with libsmi 0.5.0, with Minizip-ng , with
QtMultimedia, with automatic updates using WinSparkle 0.8.0, with AirPcap, with
binary plugins.

Running on 64-bit Windows 11 (24H2), build 26100, with AMD Ryzen 9 9950X3D
16-Core Processor (with SSE4.2), with 65175 MB of physical memory, with GLib
2.80.0, with Qt 6.5.3, with Npcap version 1.79, based on libpcap version 1.10.4,
with PCRE2 10.43 2024-02-16, with c-ares 1.27.0, with GnuTLS 3.8.4, with Gcrypt
1.10.2-unknown, with nghttp2 1.62.1, with nghttp3 0.14.0, with brotli 1.0.9,
with LZ4 1.9.4, with Zstandard 1.5.6, without AirPcap, with dark display mode,
without HiDPI, with QPA plugin "windows", with LC_TYPE=English_United
Kingdom.utf8, binary plugins supported.

This example I'm doing it locally, not even SSH (which I thought was the only thing, but seems not), I'm running a service on port 8081, so I've added HTTP decoding: Decode As

This is what get: Main

You can make out JSON traffic, but it's not being neatly decoded: JSON