Display Filter Reference
Wireshark's most powerful feature is its vast array of display filters
(over 103000 fields in 1100 protocols as of version
1.6.5). They let you drill down to the exact traffic you
want to see and are the basis of many of Wireshark's other features,
such as the coloring rules.
This is a reference. For general help using display filters, please see
the wireshark-filter
manual page, the User's Guide.
Index
1
2
3
6
9
A
B
C
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
1
2
3
6
9
A
aal1: ATM AAL1
(1.0.0 to 1.6.5, 0 fields)
aal3_4: ATM AAL3/4
(1.0.0 to 1.6.5, 0 fields)
agentx:
AgentX
(1.0.0 to 1.6.5, 36 fields)
aim_adverts: AIM Advertisements
(1.0.0 to 1.6.5, 0 fields)
aim_chat: AIM Chat Service
(1.0.0 to 1.6.5, 0 fields)
aim_chatnav: AIM Chat Navigation
(1.0.0 to 1.6.5, 0 fields)
aim_dir: AIM Directory Search
(1.0.0 to 1.6.5, 0 fields)
aim_email: AIM E-mail
(1.0.0 to 1.6.5, 0 fields)
aim_icq:
AIM ICQ
(1.0.0 to 1.6.5, 6 fields)
aim_invitation: AIM Invitation Service
(1.0.0 to 1.6.5, 0 fields)
aim_oft: AIM OFT
(1.0.0 to 1.6.5, 0 fields)
aim_popup: AIM Popup
(1.0.0 to 1.6.5, 0 fields)
aim_stats: AIM Statistics
(1.0.0 to 1.6.5, 0 fields)
aim_translate: AIM Translate
(1.0.0 to 1.6.5, 0 fields)
ams:
AMS
(1.0.0 to 1.6.5, 65 fields)
ansi_a_dtap: ANSI A-I/F DTAP
(1.0.0 to 1.6.5, 0 fields)
arcnet:
ARCNET
(1.0.0 to 1.6.5, 7 fields)
artnet:
Art-Net
(1.0.0 to 1.6.5, 143 fields)
asn1: ASN.1 decoding
(1.0.0 to 1.6.5, 0 fields)
B
bacp: PPP Bandwidth Allocation Control Protocol
(1.0.0 to 1.6.5, 0 fields)
bap: PPP Bandwidth Allocation Protocol
(1.0.0 to 1.6.5, 0 fields)
bittorrent:
BitTorrent
(1.0.0 to 1.6.5, 30 fields)
brdwlk:
Boardwalk
(1.0.0 to 1.6.5, 15 fields)
btdun: Bluetooth DUN Packet
(1.6.0 to 1.6.5, 0 fields)
btdun.atcmd: AT Cmd
(1.6.0 to 1.6.5, 0 fields)
btspp: Bluetooth SPP Packet
(1.6.0 to 1.6.5, 0 fields)
C
camel:
Camel
(1.0.0 to 1.6.5, 482 fields)
cba_acco_cb2: ICBAAccoCallback2
(1.0.0 to 1.6.5, 0 fields)
cba_acco_mgt2: ICBAAccoMgt2
(1.0.0 to 1.6.5, 0 fields)
cba_acco_server2: ICBAAccoServer2
(1.0.0 to 1.6.5, 0 fields)
cba_acco_server_srt: ICBAAccoServerSRT
(1.0.0 to 1.6.5, 0 fields)
cba_acco_sync: ICBAAccoSync
(1.0.0 to 1.6.5, 0 fields)
cba_browse:
ICBABrowse
(1.0.0 to 1.6.5, 20 fields)
cba_browse2: ICBABrowse2
(1.0.0 to 1.6.5, 0 fields)
cba_grouperror: ICBAGroupError
(1.0.0 to 1.6.5, 0 fields)
cba_grouperror_event: ICBAGroupErrorEvent
(1.0.0 to 1.6.5, 0 fields)
cba_ldev: ICBALogicalDevice
(1.0.0 to 1.6.5, 0 fields)
cba_ldev2: ICBALogicalDevice2
(1.0.0 to 1.6.5, 0 fields)
cba_pdev2: ICBAPhysicalDevice2
(1.0.0 to 1.6.5, 0 fields)
cba_pdev_pc: ICBAPhysicalDevicePC
(1.0.0 to 1.6.5, 0 fields)
cba_pdev_pc_event: ICBAPhysicalDevicePCEvent
(1.0.0 to 1.6.5, 0 fields)
cba_persist: ICBAPersist
(1.0.0 to 1.6.5, 0 fields)
cba_persist2: ICBAPersist2
(1.0.0 to 1.6.5, 0 fields)
cba_rtauto: ICBARTAuto
(1.0.0 to 1.6.5, 0 fields)
cba_rtauto2: ICBARTAuto2
(1.0.0 to 1.6.5, 0 fields)
cba_state: ICBAState
(1.0.0 to 1.6.5, 0 fields)
cba_state_event: ICBAStateEvent
(1.0.0 to 1.6.5, 0 fields)
cba_sysprop: ICBASystemProperties
(1.0.0 to 1.6.5, 0 fields)
cba_time: ICBATime
(1.0.0 to 1.6.5, 0 fields)
cbcp: PPP Callback Control Protocol
(1.0.0 to 1.6.5, 0 fields)
ccp: PPP Compression Control Protocol
(1.0.0 to 1.6.5, 0 fields)
ccsds:
CCSDS
(1.0.0 to 1.6.5, 28 fields)
cdpcp: PPP CDP Control Protocol
(1.0.0 to 1.6.5, 0 fields)
cipcco: CIP Connection Configuration Object
(1.4.0 to 1.6.5, 0 fields)
cipcls: CIP Class Generic
(1.4.0 to 1.6.5, 0 fields)
cipmr: CIP Message Router
(1.4.0 to 1.6.5, 0 fields)
clacse: ISO 10035-1 OSI Connectionless Association Control Service
(1.4.0 to 1.6.5, 0 fields)
cldap: Connectionless Lightweight Directory Access Protocol
(1.0.0 to 1.6.5, 0 fields)
clpres: ISO 9576-1 OSI Connectionless Presentation Protocol
(1.4.0 to 1.6.5, 0 fields)
clsp: ISO 9548-1 OSI Connectionless Session Protocol
(1.4.0 to 1.6.5, 0 fields)
comp_data: PPP Compressed Datagram
(1.0.0 to 1.6.5, 0 fields)
crtp:
CRTP
(1.0.0 to 1.6.5, 6 fields)
csm_encaps:
CSM_ENCAPS
(1.0.0 to 1.6.5, 54 fields)
D
data:
Data
(1.0.0 to 1.6.5, 4 fields)
data-l1-events: Layer 1 Event Messages
(1.2.0 to 1.6.5, 0 fields)
data-text-lines: Line-based text data
(1.0.0 to 1.6.5, 0 fields)
db-lsp-disc: Dropbox LAN sync Discovery Protocol
(1.4.0 to 1.6.5, 0 fields)
dcm:
DICOM
(1.0.0 to 1.0.16, 16 fields)
dcom:
DCOM
(1.0.0 to 1.6.5, 88 fields)
dhcpv6:
DHCPv6
(1.0.0 to 1.6.5, 24 fields)
diameter.3gpp.ipaddr: IPv4 Address
(1.0.0, 0 fields)
diameter.3gpp.mbms_required_qos_prio: Allocation/Retention Priority
(1.0.0, 0 fields)
diameter.3gpp.mbms_service_id: MBMS Service ID
(1.0.0, 0 fields)
diameter.3gpp.tmgi: TMGI
(1.0.0, 0 fields)
dicom:
DICOM
(1.2.0 to 1.6.5, 45 fields)
dlsw: Data Link SWitching
(1.0.0 to 1.6.5, 0 fields)
dnsserver:
DNS Server
(1.0.0 to 1.6.5, 141 fields)
drda:
DRDA
(1.0.0 to 1.6.5, 17 fields)
drsuapi:
DRSUAPI
(1.0.0 to 1.6.5, 415 fields)
E
echo:
Echo
(1.0.0 to 1.6.5, 3 fields)
ehs:
EHS
(1.2.0 to 1.6.5, 120 fields)
enttec:
ENTTEC
(1.0.0 to 1.6.5, 17 fields)
epm4: DCE/RPC Endpoint Mapper v4
(1.0.0 to 1.6.5, 0 fields)
eth:
Ethernet
(1.0.0 to 1.6.5, 12 fields)
etheric:
Etheric
(1.0.0 to 1.2.18, 27 fields)
F
fcgi:
FastCGI
(1.6.0 to 1.6.5, 12 fields)
fcip:
FCIP
(1.0.0 to 1.6.5, 26 fields)
flip:
NSN FLIP
(1.4.0 to 1.6.5, 9 fields)
fp:
FP
(1.0.0 to 1.6.5, 131 fields)
fp_hint:
FP Hint
(1.4.0 to 1.6.5, 22 fields)
frame:
Frame
(1.0.0 to 1.6.5, 20 fields)
ftp-data: FTP Data
(1.0.0 to 1.6.5, 0 fields)
G
g723:
G.723
(1.0.0 to 1.6.5, 2 fields)
giop-coseventcomm: Coseventcomm Dissector Using GIOP API
(1.0.0 to 1.6.5, 0 fields)
giop-cosnaming: Cosnaming Dissector Using GIOP API
(1.0.0 to 1.6.5, 0 fields)
giop-parlay: Parlay Dissector Using GIOP API
(1.0.0 to 1.6.5, 0 fields)
giop-tango: Tango Dissector Using GIOP API
(1.0.0 to 1.6.5, 0 fields)
goose:
GOOSE
(1.2.0 to 1.6.5, 53 fields)
gopher:
Gopher
(1.6.0 to 1.6.5, 8 fields)
gpef:
GPEF
(1.2.0 to 1.6.5, 8 fields)
gprscdr:
GPRS CDR
(1.6.0 to 1.6.5, 154 fields)
gsm_a_ccch:
GSM CCCH
(1.0.0 to 1.6.5, 315 fields)
gsm_a_sacch:
GSM SACCH
(1.2.0 to 1.6.5, 1 field)
H
h221nonstd: H221NonStandard
(1.0.0 to 1.6.5, 0 fields)
h223_bitswapped: Bitswapped ITU-T Recommendation H.223
(1.0.0 to 1.4.11, 0 fields)
h248an:
H.248.7
(1.0.0 to 1.6.5, 13 fields)
h248chp:
H.248.10
(1.0.0 to 1.6.5, 2 fields)
h263data: ITU-T Recommendation H.263
(1.0.0 to 1.0.16, 0 fields)
h264:
H.264
(1.0.0 to 1.6.5, 128 fields)
h323:
H.323
(1.0.0 to 1.6.5, 27 fields)
hyperscsi:
HyperSCSI
(1.0.0 to 1.6.5, 6 fields)
I
ifcp:
iFCP
(1.0.0 to 1.6.5, 21 fields)
ilmi: ILMI
(1.0.0 to 1.6.5, 0 fields)
infiniband:
InfiniBand
(1.0.0 to 1.6.5, 482 fields)
ipars: International Passenger Airline Reservation System
(1.0.0 to 1.6.5, 0 fields)
ipcp: PPP IP Control Protocol
(1.0.0 to 1.6.5, 0 fields)
ipsictl:
IPSICTL
(1.2.0 to 1.6.5, 7 fields)
ipv6cp: PPP IPv6 Control Protocol
(1.0.0 to 1.6.5, 0 fields)
ipxwan:
IPX WAN
(1.0.0 to 1.6.5, 19 fields)
iscsi:
iSCSI
(1.0.0 to 1.6.5, 104 fields)
isdn:
ISDN
(1.0.0 to 1.6.5, 1 field)
isns:
iSNS
(1.0.0 to 1.6.5, 101 fields)
iuup:
IuUP
(1.0.0 to 1.6.5, 1323 fields)
J
juniper:
Juniper
(1.0.0 to 1.6.5, 18 fields)
jxta:
JXTA P2P
(1.0.0 to 1.6.5, 49 fields)
jxta.message: JXTA Message
(1.0.0 to 1.6.5, 0 fields)
K
k12:
K12xx
(1.0.0 to 1.6.5, 6 fields)
kerberos:
Kerberos
(1.0.0 to 1.6.5, 181 fields)
L
lane: ATM LAN Emulation
(1.0.0 to 1.6.5, 0 fields)
laplink:
Laplink
(1.0.0 to 1.6.5, 5 fields)
lcp: PPP Link Control Protocol
(1.0.0 to 1.6.5, 0 fields)
lwapp-cntl: LWAPP Control Message
(1.0.0 to 1.6.5, 0 fields)
lwapp-l3: LWAPP Layer 3 Packet
(1.0.0 to 1.6.5, 0 fields)
M
mac:
MAC
(1.4.0 to 1.6.5, 5 fields)
mac-lte:
MAC-LTE
(1.2.0 to 1.6.5, 124 fields)
malformed: Malformed Packet
(1.0.0 to 1.6.5, 0 fields)
mate: Meta Analysis Tracing Engine
(1.0.0 to 1.6.5, 0 fields)
media: Media Type
(1.0.0 to 1.6.5, 0 fields)
megaco:
MEGACO
(1.0.0 to 1.6.5, 47 fields)
message-http: Media Type: message/http
(1.0.0 to 1.6.5, 0 fields)
meta:
Metadata
(1.4.0 to 1.6.5, 28 fields)
mibs:
MIBs
(1.0.3 to 1.0.5, 1.0.9 to 1.0.16, 1.2.1 to 1.2.18, 759 fields)
mms:
MMS
(1.0.0 to 1.6.5, 446 fields)
mp4v-es:
MP4V-ES
(1.2.0 to 1.6.5, 15 fields)
mpeg: Moving Picture Experts Group
(1.0.0 to 1.6.5, 0 fields)
mplscp: PPP MPLS Control Protocol
(1.0.0 to 1.6.5, 0 fields)
mplspwatmcell:
ATM Cell
(1.4.0 to 1.6.5, 1 field)
msnms: MSN Messenger Service
(1.0.0 to 1.6.5, 0 fields)
N
nbipx: NetBIOS over IPX
(1.0.0 to 1.6.5, 0 fields)
netbios:
NetBIOS
(1.0.0 to 1.6.5, 33 fields)
nfsacl:
NFSACL
(1.0.0 to 1.6.5, 11 fields)
nfsauth:
NFSAUTH
(1.0.0 to 1.6.5, 1 field)
nisplus:
NIS+
(1.0.0 to 1.6.5, 118 fields)
nmpi: Name Management Protocol over IPX
(1.0.0 to 1.6.5, 0 fields)
nw_serial: NetWare Serialization Protocol
(1.0.0 to 1.6.5, 0 fields)
O
oamaal: ATM OAM AAL
(1.0.0 to 1.6.5, 0 fields)
opensafety:
openSAFETY
(1.6.0 to 1.6.5, 47 fields)
osi: OSI
(1.0.0 to 1.6.5, 0 fields)
osicp: PPP OSI Control Protocol
(1.0.0 to 1.6.5, 0 fields)
P
p3: X.411 Message Access Service
(1.4.0 to 1.6.5, 0 fields)
pcnfsd:
PC NFS
(1.0.0 to 1.6.5, 15 fields)
pdcp-lte:
PDCP-LTE
(1.2.0 to 1.6.5, 114 fields)
pkcs-1:
PKCS#1
(1.0.0 to 1.6.5, 11 fields)
pkinit:
PKINIT
(1.0.0 to 1.6.5, 22 fields)
portmap:
Portmap
(1.0.0 to 1.6.5, 19 fields)
ppp_hdlc: PPP In HDLC-Like Framing
(1.0.0 to 1.6.5, 0 fields)
pppmux: PPP Multiplexing
(1.0.0 to 1.6.5, 0 fields)
pppmuxcp: PPPMux Control Protocol
(1.0.0 to 1.6.5, 0 fields)
pw_atm_n2o_nocw: ATM PW, N-to-one Cell Mode (no CW)
(1.2.0 to 1.2.18, 0 fields)
pw_hdlc_nocw_hdlc_ppp: HDLC-like framing for PPP
(1.2.0 to 1.6.5, 0 fields)
pwach: PW Associated Channel Header
(1.2.0 to 1.6.5, 0 fields)
pwethheuristic: Ethernet PW (CW heuristic)
(1.2.0 to 1.6.5, 0 fields)
pwethnocw: Ethernet PW (no CW)
(1.2.0 to 1.6.5, 0 fields)
pwmcw: PW MPLS Control Word (generic/preferred)
(1.2.0 to 1.6.5, 0 fields)
Q
q2931:
Q.2931
(1.0.0 to 1.6.5, 9 fields)
q931:
Q.931
(1.0.0 to 1.6.5, 47 fields)
q932:
Q.932
(1.0.0 to 1.6.5, 39 fields)
q933:
Q.933
(1.0.0 to 1.6.5, 23 fields)
qsig:
QSIG
(1.0.0 to 1.6.5, 744 fields)
R
radio: 802.11 radio information
(1.0.0 to 1.6.5, 0 fields)
raw: Raw packet data
(1.0.0 to 1.6.5, 0 fields)
raw_sigcomp: Decompressed SigComp message as raw text
(1.0.0 to 1.6.5, 0 fields)
redback:
Redback
(1.0.0 to 1.6.5, 9 fields)
remunk2: IRemUnknown2
(1.0.0 to 1.6.5, 0 fields)
ripng:
RIPng
(1.0.0 to 1.6.5, 8 fields)
rlc:
RLC
(1.4.0 to 1.6.5, 29 fields)
rlc-lte:
RLC-LTE
(1.2.0 to 1.6.5, 53 fields)
rmi:
Java RMI
(1.0.0 to 1.6.5, 10 fields)
rss:
rss
(1.0.0 to 1.6.5, 122 fields)
rstat:
RSTAT
(1.0.0 to 1.6.5, 4 fields)
rtcfg:
RTcfg
(1.0.0 to 1.6.5, 23 fields)
S
sadmind:
SADMIND
(1.0.0 to 1.6.5, 3 fields)
scsi:
SCSI
(1.0.0 to 1.6.5, 199 fields)
scsi_mmc:
SCSI_MMC
(1.0.0 to 1.6.5, 145 fields)
scsi_osd:
SCSI_OSD
(1.0.0 to 1.6.5, 82 fields)
scsi_sbc:
SCSI_SBC
(1.0.0 to 1.6.5, 72 fields)
scsi_smc:
SCSI_SMC
(1.0.0 to 1.6.5, 17 fields)
scsi_ssc:
SCSI_SSC
(1.0.0 to 1.6.5, 41 fields)
serialization: Java Serialization
(1.0.0 to 1.6.5, 0 fields)
sgimount: SGI Mount Service
(1.0.0 to 1.6.5, 0 fields)
short: Short Frame
(1.0.0 to 1.6.5, 0 fields)
sipfrag:
Sipfrag
(1.0.0 to 1.6.5, 1 field)
sna_xid: Systems Network Architecture XID
(1.0.0 to 1.6.5, 0 fields)
spnego-krb5: SPNEGO-KRB5
(1.0.0 to 1.6.5, 0 fields)
spray:
SPRAY
(1.0.0 to 1.6.5, 6 fields)
sscf-nni:
SSCF-NNI
(1.0.0 to 1.6.5, 2 fields)
sscop:
SSCOP
(1.0.0 to 1.6.5, 8 fields)
starteam:
StarTeam
(1.0.0 to 1.6.5, 17 fields)
synergy:
Synergy
(1.0.0 to 1.6.5, 60 fields)
T
t30:
T.30
(1.0.0 to 1.6.5, 103 fields)
t38:
T.38
(1.0.0 to 1.6.5, 39 fields)
tacacs:
TACACS
(1.0.0 to 1.6.5, 13 fields)
tacplus:
TACACS+
(1.0.0 to 1.6.5, 12 fields)
tcpcl: DTN TCP Convergence Layer Protocol
(1.4.0 to 1.6.5, 0 fields)
tdma: TDMA RTmac Discipline
(1.0.0 to 1.6.5, 0 fields)
teklink:
TEKLINK
(1.6.0 to 1.6.5, 18 fields)
telnet:
Telnet
(1.0.0 to 1.6.5, 11 fields)
trill:
TRILL
(1.4.0 to 1.6.5, 8 fields)
U
udpencap: UDP Encapsulation of IPsec Packets
(1.0.0 to 1.6.5, 0 fields)
unreassembled: Unreassembled Fragmented Packet
(1.0.0 to 1.6.5, 0 fields)
usb:
USB
(1.0.0 to 1.6.5, 84 fields)
usbhid:
USB HID
(1.4.0 to 1.6.5, 52 fields)
usbhub:
USB HUB
(1.4.0 to 1.6.5, 17 fields)
user_dlt: DLT User
(1.0.0 to 1.6.5, 0 fields)
V
v52:
V5.2
(1.4.0 to 1.6.5, 67 fields)
vcdu:
VCDU
(1.2.0 to 1.6.5, 26 fields)
vines_arp: Banyan Vines ARP
(1.0.0 to 1.6.5, 0 fields)
vines_echo: Banyan Vines Echo
(1.0.0 to 1.6.5, 0 fields)
vines_frp: Banyan Vines Fragmentation Protocol
(1.0.0 to 1.6.5, 0 fields)
vines_icp: Banyan Vines ICP
(1.0.0 to 1.6.5, 0 fields)
vines_ipc: Banyan Vines IPC
(1.0.0 to 1.6.5, 0 fields)
vines_llc: Banyan Vines LLC
(1.0.0 to 1.6.5, 0 fields)
vines_rtp: Banyan Vines RTP
(1.0.0 to 1.6.5, 0 fields)
vines_spp: Banyan Vines SPP
(1.0.0 to 1.6.5, 0 fields)
vsncp: Vendor Specific Control Protocol
(1.4.0 to 1.6.5, 0 fields)
W
who:
Who
(1.0.0 to 1.6.5, 14 fields)
wpan-nonask-phy: IEEE 802.15.4 Low-Rate Wireless PAN non-ASK PHY
(1.2.0 to 1.6.5, 0 fields)
X
x.25:
X.25
(1.0.0 to 1.0.16, 17 fields)
x.29:
X.29
(1.0.0 to 1.0.16, 3 fields)
x11:
X11
(1.0.0 to 1.6.5, 6659 fields)
x25:
X.25
(1.2.0 to 1.6.5, 19 fields)
x29:
X.29
(1.2.0 to 1.6.5, 3 fields)
xyplex:
Xyplex
(1.0.0 to 1.6.5, 6 fields)
Y
Z
zrtp:
ZRTP
(1.2.0 to 1.6.5, 44 fields)