Public bug reported: Please see attached screenshot for example. tcpdump on Ubuntu 12.04 also can't decode the file properly and may be related. Please see bug # 1002138. The packets can be decoded properly by tcpdump on OpenBSD 5.0 itself. The packets can also be decoded properly by the version of Wireshark in Ubuntu 10.04.
The first 10 packets decoded by tcpdump on OpenBSD 5.0 are the following: # tcpdump -r pflog -c 10 tcpdump: WARNING: snaplen raised from 116 to 1500 11:00:03.879369 0.0.0.0.bootpc > 255.255.255.255.bootps: xid:0x120034 flags:0x8000 ether 00:1e:c1:0a:cc:e7 vend-rfc1048 DHCP:DISCOVER PR:SM+DG+NS+HN+DN+RP+YD 11:00:03.879390 0.0.0.0.bootpc > 255.255.255.255.bootps: xid:0x120034 flags:0x8000 ether 00:1e:c1:0a:cc:e7 vend-rfc1048 DHCP:DISCOVER PR:SM+DG+NS+HN+DN+RP+YD 11:00:05.303412 0.0.0.0.bootpc > 255.255.255.255.bootps: xid:0x120034 flags:0x8000 ether 00:1e:c1:0a:ce:27 vend-rfc1048 DHCP:DISCOVER PR:SM+DG+NS+HN+DN+RP+YD 11:00:05.303436 0.0.0.0.bootpc > 255.255.255.255.bootps: xid:0x120034 flags:0x8000 ether 00:1e:c1:0a:ce:27 vend-rfc1048 DHCP:DISCOVER PR:SM+DG+NS+HN+DN+RP+YD 11:00:06.074715 0.0.0.0.bootpc > 255.255.255.255.bootps: xid:0x120034 flags:0x8000 ether 00:1e:c1:0a:cc:e7 vend-rfc1048 DHCP:DISCOVER PR:SM+DG+NS+HN+DN+RP+YD 11:00:06.074746 0.0.0.0.bootpc > 255.255.255.255.bootps: xid:0x120034 flags:0x8000 ether 00:1e:c1:0a:cc:e7 vend-rfc1048 DHCP:DISCOVER PR:SM+DG+NS+HN+DN+RP+YD 11:00:10.781760 0.0.0.0.bootpc > 255.255.255.255.bootps: xid:0x120034 flags:0x8000 ether 00:1e:c1:0a:ce:27 vend-rfc1048 DHCP:DISCOVER PR:SM+DG+NS+HN+DN+RP+YD 11:00:10.781785 0.0.0.0.bootpc > 255.255.255.255.bootps: xid:0x120034 flags:0x8000 ether 00:1e:c1:0a:ce:27 vend-rfc1048 DHCP:DISCOVER PR:SM+DG+NS+HN+DN+RP+YD 11:00:11.552526 0.0.0.0.bootpc > 255.255.255.255.bootps: xid:0x120034 flags:0x8000 ether 00:1e:c1:0a:cc:e7 vend-rfc1048 DHCP:DISCOVER PR:SM+DG+NS+HN+DN+RP+YD 11:00:11.552550 0.0.0.0.bootpc > 255.255.255.255.bootps: xid:0x120034 flags:0x8000 ether 00:1e:c1:0a:cc:e7 vend-rfc1048 DHCP:DISCOVER PR:SM+DG+NS+HN+DN+RP+YD ** Affects: wireshark (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1002142 Title: Can't decode OpenBSD 5.0 pflog files properly on Ubuntu 12.04 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/wireshark/+bug/1002142/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs