Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

The wireshark-filter man page is probably the best place to go for a description of the slice operator. But using the slice operator requires that you know much more information about the field such as its offset and length than simply filtering by field name, so in general I'd say that using the field name is going to be much easier and convenient in most cases.

The wireshark-filter man page is probably the best place to go for a description of the slice operator. But using the slice operator requires that you know much more information about the field such as its offset and length than simply filtering by field name, so in general I'd say that using the field name is going to be much easier and more convenient in most cases.