SIP DisplayFilter doesn't work in Wireshark 4

asked 2022-10-27 09:37:21 +0000

asterisk


This SIP Display filter doesn't no longer work in Wireshark 4.

I normally use SIP contains <number> when I'm looking for an trace but that does not show any results anymore. When I did open the same file in Wireshark 3.6 it worked as intended.


1 Answer

answered 2022-10-27 12:31:23 +0000

Chuckc

updated 2022-10-27 12:42:39 +0000

Are you searching for a <number> or a "string that respresents <number>"?

There have been changes to how display filters work: What’s New In Wireshark 4.0?

Sample capture: aaa.pcap Sample SIP and RTP traffic.

sip contains "97239287044"

Measurement             Captured              Displayed              Marked
Packets                   691                 33 (4.8%)                         —

Case matters - using SIP or sip?

(Version 4.0.1 (v4.0.1-0-ge9f3970b1527).)

Ah I did notice now that it seems to require "" around the number, did download the aaa.pcap and tried with it. In Wireshark 4 you must type sip contains "351047" to make it work.

asterisk

