This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

filter by field value

0

I've used the following to filter by field value - udp port 8003 and udp[10] = 200; udp port 8002 and udp[8:4] = 1049.

I recently attempted these with a newer version of Wireshark and they were disallowed. Can you help me update these?

asked 30 Dec '13, 08:22

mmaloney's gravatar image

mmaloney
11112
accept rate: 0%


One Answer:

0

Are you entering them as capture filters or as display filters? Wireshark 1.10.5 accepts both of these as legitimate capture filters.

answered 30 Dec '13, 09:14

Jim%20Aragon's gravatar image

Jim Aragon
7.2k733118
accept rate: 24%