You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Lua向Wireshark自定义列写入内容?

问题解决方法

你的需求完全可行,问题出在自定义列的访问方式上——Wireshark的Lua API中,自定义列无法通过pinfo.cols.自定义列名直接访问,需要使用正确的API方法设置值。

修正后的代码

将原代码中pinfo.cols.customDienstname:set("MEIN SERVICE")替换为以下任一方式即可:

方式1:通过ProtoField的唯一标识设置

直接使用你定义的ProtoField名称(customDienstname)来指定列:

pinfo.cols:set("customDienstname", "MEIN SERVICE")

方式2:通过自定义列的显示名称设置

如果你的自定义列在Wireshark界面中显示的名称是Dienstname(对应ProtoField的显示名),可以用该名称设置:

pinfo.cols:set("Dienstname", "MEIN SERVICE")

完整修正代码

local dienstname_f = ProtoField.string("customDienstname", "Dienstname")
local custom_proto = Proto("custom", "Custom Dienst")
custom_proto.fields = {dienstname_f}

function custom_proto.dissector(buffer, pinfo, tree)
    if (tostring(pinfo.src) == "10.0.0.0" and pinfo.src_port == 5000) or
       (tostring(pinfo.dst) == "10.0.0.0" and pinfo.dst_port == 5000) then
       
        pinfo.cols.info:set("Hallo2 von Lua!")
        -- 替换原自定义列设置逻辑
        pinfo.cols:set("customDienstname", "MEIN SERVICE")

        local subtree = tree:add(custom_proto, "Custom Dienst")
        subtree:add(dienstname_f, "MEIN SERVICE")
    end
end

register_postdissector(custom_proto)

额外注意事项

  • 确保Wireshark中添加的自定义列,其「Field name」设置为customDienstname(与ProtoField名称一致),类型选择「Custom」。
  • 若存在多个自定义列,也可通过序号访问:pinfo.cols.custom[序号]:set(值),序号从1开始计数。

内容的提问来源于stack exchange,提问作者Vincent

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 16:12:13