Ask Your Question

Capture from only one Port in wireshark and tshark

asked 2018-06-13 04:24:52 +0000

this post is marked as community wiki

This post is a wiki. Anyone with karma >750 is welcome to improve it.

hi, is it possible to capture from only one port in wireshark and tshark? in wireshark if we use udp.port==1000 in filter tab, all packets capture but only packets with udp.port==1000 are displayed. However i want to capture packets of only one port?

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted

answered 2018-06-13 04:38:03 +0000

Guy Harris gravatar image

However i want to capture packets of only one port?

That's what capture filters are for.

Those are implemented by libpcap/WinPcap, and (due to the way they're implemented, often in the kernel-mode networking stack) have limited capabilities, so their syntax is different.

The capture filter you'd want would be udp port 1000.

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2018-06-13 04:24:52 +0000

Seen: 789 times

Last updated: Jun 13 '18