Wireshark - 1.0 Betriebsanweisung Seite 127

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 284
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 126
6.3. Filtering packets while viewing
Wireshark has two filtering languages: One used when capturing packets, and one used when dis-
playing packets. In this section we explore that second type of filter: Display filters. The first one
has already been dealt with in Section 4.9, “Filtering while capturing”.
Display filters allow you to concentrate on the packets you are interested in while hiding the cur-
rently uninteresting ones. They allow you to select packets by:
Protocol
The presence of a field
The values of fields
A comparison between fields
... and a lot more!
To select packets based on protocol type, simply type the protocol in which you are interested in the
Filter: field in the filter toolbar of the Wireshark window and press enter to initiate the filter. Fig-
ure 6.5, “Filtering on the TCP protocol” shows an example of what happens when you type tcp in
the filter field.
Note!
All protocol and field names are entered in lowercase. Also, don't forget to press enter
after entering the filter expression.
Figure 6.5. Filtering on the TCP protocol
Working with captured packets
112
Seitenansicht 126
1 2 ... 122 123 124 125 126 127 128 129 130 131 132 ... 283 284

Kommentare zu diesen Handbüchern

Keine Kommentare