Project

General

Profile

Actions

Bug #6954

open

eve: packet field packet_info.linktype is non-portable

Added by Victor Julien about 1 month ago. Updated 26 days ago.

Status:
In Review
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

This field holds a numeric representation of the linktype/datalink, but this number can differ between operating systems. Most notably DLT_RAW is has value 12 on linux and 14 on OpenBSD.

It would probably be best to use a string representation. Following capinfos might make sense:

File encapsulation:  Raw IP

Interface #0 info:
                     Encapsulation = Raw IP (7 - rawip)

Could do "Raw IP" or follow the "rawip" notation.

Regardless this should be in a new field.

Actions #1

Updated by Jeff Lucovsky 29 days ago

A simple solution would use the interface pcap_datalink_val_to_name to get the display name for the datalink value.

Actions #2

Updated by Jeff Lucovsky 26 days ago

  • Status changed from New to In Review
  • Assignee changed from OISF Dev to Jeff Lucovsky
Actions

Also available in: Atom PDF