Can this packet be filtered?

asked 2025-12-25 06:46:53 +0000

I have a large file with more than 90% of packets coming from one IP. If I was to filter based on IP, I would have to save 90% of the large capture file I have which I'd like to avoid.

Is there any way to specify just one packet with the following details that I got from my IDS?

TIME:              11/06/2025-16:57:44.496934
PKT SRC:           wire/pcap
SRC IP:            redacted1
DST IP:            redacted2
PROTO:             17
SRC PORT:          41893
DST PORT:          45547
FLOW:              to_server: FALSE, to_client: TRUE
FLOW Start TS:     11/06/2025-16:34:02.883356
FLOW PKTS TODST:   28056
FLOW PKTS TOSRC:   43406
FLOW Total Bytes:  58085272
FLOW IPONLY SET:   TOSERVER: TRUE, TOCLIENT: TRUE
FLOW ACTION:       DROP: FALSE
FLOW NOINSPECTION: PACKET: FALSE, PAYLOAD: FALSE, APP_LAYER: FALSE
FLOW APP_LAYER:    DETECTED: TRUE, PROTO 34
PACKET LEN:        1494
edit retag flag offensive close merge delete