Establishing a display filter that hides VMWare frames and packets.

I've been trying to figure out a display filter that will allow me to hide packets from VMWare. I've tried using eth.addr but without success. eth.addr matches "^00:0c:29:" would in my mind check that the first three bytes matched; however, this does not appear to be the case. Any ideas on how to make this work?

As mentioned in the wireshark-filter man page, the matches (or ~) operator "is only implemented for protocols and for protocol fields with a text string representation.", of which the Ethernet source and destination MAC addresses are not.

In any case, I think you can use the slice operator to achieve your goal, for example:

eth.addr[0:3] == 00:0c:29
Thank you. the slice suggestion appears to work for my purposes.

