6.4. Building display filter expressions

Wireshark 2.1

6.4. Building display filter expressions

[Tip] Tip

6.4.1. Display filter fields

6.4.2. Comparing values

[Tip] Tip
English C-like Description and example
udp contains 81:60:03
sip.To contains "a1762"
http.host matches "acme\.(org|com|net)"
tcp.flags & 0x02

6.4.3. Combining expressions

English C-like Description and example

6.4.4. Substring Operator

eth.src[0:3] == 00:00:83
eth.src[1-2] == 00:83
eth.src[:4] == 00:00:83:00
eth.src[4:] == 20:20
eth.src[2] == 83
eth.src[0:3,1-2,:4,4:,2] ==
00:00:83:00:83:00:00:83:00:20:20:83

6.4.5. Membership Operator.

tcp.port in {80 443 8080}
tcp.port == 80 || tcp.port == 443 || tcp.port == 8080

6.4.6. A Common Mistake