6.4. Building display filter expressions

Wireshark

6.4. Building display filter expressions

[Tip] Tip!

6.4.1. Display filter fields

6.4.2. Comparing values

[Tip] Tip!
English C-like Description and example
eq
==
ip.src==10.0.0.5
ne
!=
ip.src!=10.0.0.5
gt
>
frame.len > 10
lt
<
frame.len < 128
ge
>=
frame.len ge 0x100
le
<=
frame.len <= 0x20
Type Example
Unsigned integer (8-bit, 16-bit, 24-bit, 32-bit)
ip.len le 1500
ip.len le 02734
ip.len le 0x436
            
Signed integer (8-bit, 16-bit, 24-bit, 32-bit)  
Boolean
Ethernet address (6 bytes)
eth.dst == ff:ff:ff:ff:ff:ff
eth.dst == ff-ff-ff-ff-ff-ff
eth.dst == ffff.ffff.ffff
IPv4 address
IPv6 address ipv6.addr == ::1
IPX address ipx.addr == 00000000.ffffffffffff
String (text) http.request.uri == "http://www.wireshark.org/"

6.4.3. Combining expressions

English C-like Description and example
and &&
ip.src==10.0.0.5 and tcp.flags.fin
or ||
ip.scr==10.0.0.5 or ip.src==192.1.1.1
xor ^^
tr.dst[0:3] == 0.6.29 xor tr.src[0:3] == 0.6.29
not !
not llc
[...]  
eth.src[0:3] == 00:00:83
eth.src[1-2] == 00:83
            
eth.src[:4] == 00:00:83:00
eth.src[4:] == 20:20
eth.src[2] == 83
eth.src[0:3,1-2,:4,4:,2] == 
00:00:83:00:83:00:00:83:00:20:20:83

6.4.4. A common mistake

[Warning] Warning!