diff options
author | Gerald Combs <gerald@zing.org> | 2016-04-24 11:21:50 -0700 |
---|---|---|
committer | Anders Broman <a.broman58@gmail.com> | 2016-06-15 13:39:29 +0000 |
commit | d25a60c1c1db0d81e332272fe00ec4ef4fb03e65 (patch) | |
tree | 0a90169d7ffa2fcff67c95328328998bb654f580 /epan/packet.c | |
parent | b26e757b310180bd2ab867dd5ad0cc0261993135 (diff) |
More Sysdig / system event support.
Add REC_TYPE_SYSCALL to wiretap and use it for Sysdig events. Call the
Sysdig event dissector from the frame dissector. Create a "syscall"
protocol for system calls, but add "frame" items to it for now.
Add the ability to write Sysdig events. This lets us merge packet
capture and syscall capture files.
Change-Id: I12774ec69c89d8e329b6130c67f29aade4e3d778
Reviewed-on: https://code.wireshark.org/review/15078
Tested-by: Petri Dish Buildbot <buildbot-no-reply@wireshark.org>
Reviewed-by: Anders Broman <a.broman58@gmail.com>
Diffstat (limited to 'epan/packet.c')
-rw-r--r-- | epan/packet.c | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/epan/packet.c b/epan/packet.c index 8deef8fdef..a3b024747b 100644 --- a/epan/packet.c +++ b/epan/packet.c @@ -474,6 +474,10 @@ dissect_record(epan_dissect_t *edt, int file_type_subtype, record_type = "Report"; break; + case REC_TYPE_SYSCALL: + record_type = "System Call"; + break; + default: /* * XXX - if we add record types that shouldn't be |