Wireshark-users: [Wireshark-users] Plugging decoder scripts into Wireshark
From: Mark Dawson <Mark.Dawson@xxxxxxxxxxxxxxx>
Date: Mon, 10 May 2010 15:23:14 -0500
Title: Plugging decoder scripts into Wireshark
We have protocols that we receive from various exchanges (e.g., NASDAQ, CME, etc.) that are encoded in different ways to transport market feeds to financial firms.

We capture this data for analysis with tcpdump and analyze it with Wireshark.  However, to decode the actual packet data, we have decoder tools we run against the it to get the actual market data (e.g., 300 shares of IBM sold@$85.32).

Do any of you know if it's possible to plug into Wireshark a decoder script, possibly written in Perl/Python/C, that will decode the packet data and display in a screen?  If we could do this, we can provide our decoder scripts to people not as technically savvy so they wouldn't have to tinker with our individual decoder scripts, but could just go through a familiar Wireshark screen and search through the data.

Is this possible?


The information in this e-mail is intended only for the person or entity to which it is addressed.

It may contain confidential and /or privileged material. If someone other than the intended recipient should receive this e-mail, he / she shall not be entitled to read, disseminate, disclose or duplicate it.

If you receive this e-mail unintentionally, please inform us immediately by "reply" and then delete it from your system. Although this information has been compiled with great care, neither IMC Financial Markets & Asset Management nor any of its related entities shall accept any responsibility for any errors, omissions or other inaccuracies in this information or for the consequences thereof, nor shall it be bound in any way by the contents of this e-mail or its attachments. In the event of incomplete or incorrect transmission, please return the e-mail to the sender and permanently delete this message and any attachments.

Messages and attachments are scanned for all known viruses. Always scan attachments before opening them.