I'm generating XML-formatted output from a Wireshark dump using the following command:
tshark -r my_wireshark_data.pcap -T pdml > my_wireshark_data.xml
Looking at the XML file generated, I cannot figure out the meaning of the pos and size attributes, which appear everywhere. Can anyone explain, or provide a link to documentation?
Output snippet:
<pdml version="0" creator="wireshark/1.10.14" time="Mon Jun 20 15:27:45 2016" capture_file="my_wireshark_data.pcap">
<packet>
<proto name="ip" ...>
<field name="ip.version" showname="Version: 4" size="1" pos="14" show="4" value="45"/>
</proto>
</pdml>
Also:
Why is value set to 45
instead of 4
?
What is the difference between showname and show?