Display Filter Reference
Wireshark's most powerful feature is its vast array of display filters
(over 85000 as of version 1.2.6). They let you drill
drill down to the exact traffic you want to see and are the basis of many
of Wireshark's other features, such as the coloring rules.
This is a reference. If you need help using display filters, please see
the wireshark-filter
and the User's Guide.
Index
1
2
3
9
A
B
C
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
1
2
3
9
A
aal1: ATM AAL1
(1.0.0 to 1.2.6, 0 fields)
aal3_4: ATM AAL3/4
(1.0.0 to 1.2.6, 0 fields)
agentx:
AgentX
(1.0.0 to 1.2.6, 31 fields)
aim_adverts: AIM Advertisements
(1.0.0 to 1.2.6, 0 fields)
aim_chat: AIM Chat Service
(1.0.0 to 1.2.6, 0 fields)
aim_chatnav: AIM Chat Navigation
(1.0.0 to 1.2.6, 0 fields)
aim_dir: AIM Directory Search
(1.0.0 to 1.2.6, 0 fields)
aim_email: AIM E-mail
(1.0.0 to 1.2.6, 0 fields)
aim_icq:
AIM ICQ
(1.0.0 to 1.2.6, 6 fields)
aim_invitation: AIM Invitation Service
(1.0.0 to 1.2.6, 0 fields)
aim_oft: AIM OFT
(1.0.0 to 1.2.6, 0 fields)
aim_popup: AIM Popup
(1.0.0 to 1.2.6, 0 fields)
aim_stats: AIM Statistics
(1.0.0 to 1.2.6, 0 fields)
aim_translate: AIM Translate
(1.0.0 to 1.2.6, 0 fields)
ams:
AMS
(1.0.0 to 1.2.6, 65 fields)
ansi_a_dtap: ANSI A-I/F DTAP
(1.0.0 to 1.2.6, 0 fields)
arcnet:
ARCNET
(1.0.0 to 1.2.6, 7 fields)
artnet:
Art-Net
(1.0.0 to 1.2.6, 142 fields)
asn1: ASN.1 decoding
(1.0.0 to 1.2.6, 0 fields)
atm:
ATM
(1.0.0 to 1.2.6, 4 fields)
B
bacp: PPP Bandwidth Allocation Control Protocol
(1.0.0 to 1.2.6, 0 fields)
bap: PPP Bandwidth Allocation Protocol
(1.0.0 to 1.2.6, 0 fields)
bittorrent:
BitTorrent
(1.0.0 to 1.2.6, 28 fields)
brdwlk:
Boardwalk
(1.0.0 to 1.2.6, 15 fields)
C
camel:
Camel
(1.0.0 to 1.2.6, 479 fields)
cba_acco_cb2: ICBAAccoCallback2
(1.0.0 to 1.2.6, 0 fields)
cba_acco_mgt2: ICBAAccoMgt2
(1.0.0 to 1.2.6, 0 fields)
cba_acco_server2: ICBAAccoServer2
(1.0.0 to 1.2.6, 0 fields)
cba_acco_server_srt: ICBAAccoServerSRT
(1.0.0 to 1.2.6, 0 fields)
cba_acco_sync: ICBAAccoSync
(1.0.0 to 1.2.6, 0 fields)
cba_browse:
ICBABrowse
(1.0.0 to 1.2.6, 20 fields)
cba_browse2: ICBABrowse2
(1.0.0 to 1.2.6, 0 fields)
cba_grouperror: ICBAGroupError
(1.0.0 to 1.2.6, 0 fields)
cba_grouperror_event: ICBAGroupErrorEvent
(1.0.0 to 1.2.6, 0 fields)
cba_ldev: ICBALogicalDevice
(1.0.0 to 1.2.6, 0 fields)
cba_ldev2: ICBALogicalDevice2
(1.0.0 to 1.2.6, 0 fields)
cba_pdev2: ICBAPhysicalDevice2
(1.0.0 to 1.2.6, 0 fields)
cba_pdev_pc: ICBAPhysicalDevicePC
(1.0.0 to 1.2.6, 0 fields)
cba_pdev_pc_event: ICBAPhysicalDevicePCEvent
(1.0.0 to 1.2.6, 0 fields)
cba_persist: ICBAPersist
(1.0.0 to 1.2.6, 0 fields)
cba_persist2: ICBAPersist2
(1.0.0 to 1.2.6, 0 fields)
cba_rtauto: ICBARTAuto
(1.0.0 to 1.2.6, 0 fields)
cba_rtauto2: ICBARTAuto2
(1.0.0 to 1.2.6, 0 fields)
cba_state: ICBAState
(1.0.0 to 1.2.6, 0 fields)
cba_state_event: ICBAStateEvent
(1.0.0 to 1.2.6, 0 fields)
cba_sysprop: ICBASystemProperties
(1.0.0 to 1.2.6, 0 fields)
cba_time: ICBATime
(1.0.0 to 1.2.6, 0 fields)
cbcp: PPP Callback Control Protocol
(1.0.0 to 1.2.6, 0 fields)
ccp: PPP Compression Control Protocol
(1.0.0 to 1.2.6, 0 fields)
ccsds:
CCSDS
(1.0.0 to 1.2.6, 25 fields)
cdpcp: PPP CDP Control Protocol
(1.0.0 to 1.2.6, 0 fields)
cldap: Connectionless Lightweight Directory Access Protocol
(1.0.0 to 1.2.6, 0 fields)
comp_data: PPP Compressed Datagram
(1.0.0 to 1.2.6, 0 fields)
crtp:
CRTP
(1.0.0 to 1.2.6, 6 fields)
csm_encaps:
CSM_ENCAPS
(1.0.0 to 1.2.6, 54 fields)
D
data:
Data
(1.0.0 to 1.2.6, 2 fields)
data-l1-events: Layer 1 Event Messages
(1.2.0 to 1.2.6, 0 fields)
data-text-lines: Line-based text data
(1.0.0 to 1.2.6, 0 fields)
dcerpc:
DCE RPC
(1.0.0 to 1.2.6, 139 fields)
dcm:
DICOM
(1.0.0 to 1.2.0, 16 fields)
dcom:
DCOM
(1.0.0 to 1.2.6, 88 fields)
dhcpv6:
DHCPv6
(1.0.0 to 1.2.6, 5 fields)
diameter.3gpp.ipaddr: IPv4 Address
(1.0.0 to 1.0.1, 0 fields)
diameter.3gpp.mbms_required_qos_prio: Allocation/Retention Priority
(1.0.0 to 1.0.1, 0 fields)
diameter.3gpp.mbms_service_id: MBMS Service ID
(1.0.0 to 1.0.1, 0 fields)
diameter.3gpp.tmgi: TMGI
(1.0.0 to 1.0.1, 0 fields)
dicom:
DICOM
(1.2.0 to 1.2.6, 23 fields)
dis: Distributed Interactive Simulation
(1.0.0 to 1.2.6, 0 fields)
dlsw: Data Link SWitching
(1.0.0 to 1.2.6, 0 fields)
dnsserver:
DNS Server
(1.0.0 to 1.2.6, 141 fields)
drda:
DRDA
(1.0.0 to 1.2.6, 17 fields)
drsuapi:
DRSUAPI
(1.0.0 to 1.2.6, 415 fields)
E
echo:
Echo
(1.0.0 to 1.2.6, 3 fields)
ehs:
EHS
(1.2.0 to 1.2.6, 120 fields)
enttec:
ENTTEC
(1.0.0 to 1.2.6, 17 fields)
epm4: DCE/RPC Endpoint Mapper v4
(1.0.0 to 1.2.6, 0 fields)
eth:
Ethernet
(1.0.0 to 1.2.6, 8 fields)
etheric:
Etheric
(1.0.0 to 1.2.6, 27 fields)
F
fcip:
FCIP
(1.0.0 to 1.2.6, 26 fields)
fp:
FP
(1.0.0 to 1.2.6, 114 fields)
frame:
Frame
(1.0.0 to 1.2.6, 18 fields)
ftp-data: FTP Data
(1.0.0 to 1.2.6, 0 fields)
G
g723:
G.723
(1.0.0 to 1.2.6, 2 fields)
giop-coseventcomm: Coseventcomm Dissector Using GIOP API
(1.0.0 to 1.2.6, 0 fields)
giop-cosnaming: Cosnaming Dissector Using GIOP API
(1.0.0 to 1.2.6, 0 fields)
giop-parlay: Parlay Dissector Using GIOP API
(1.0.0 to 1.2.6, 0 fields)
giop-tango: Tango Dissector Using GIOP API
(1.0.0 to 1.2.6, 0 fields)
goose:
GOOSE
(1.2.0 to 1.2.6, 53 fields)
gpef:
GPEF
(1.2.0 to 1.2.6, 8 fields)
gsm_a_ccch:
GSM CCCH
(1.0.0 to 1.2.6, 258 fields)
gsm_a_sacch:
GSM SACCH
(1.2.0 to 1.2.6, 1 field)
H
h221nonstd: H221NonStandard
(1.0.0 to 1.2.6, 0 fields)
h223_bitswapped: Bitswapped ITU-T Recommendation H.223
(1.0.0 to 1.2.6, 0 fields)
h248an:
H.248.7
(1.0.0 to 1.2.6, 13 fields)
h248chp:
H.248.10
(1.0.0 to 1.2.6, 2 fields)
h263data: ITU-T Recommendation H.263
(1.0.0 to 1.2.0, 0 fields)
h264:
H.264
(1.0.0 to 1.2.6, 128 fields)
h323:
H.323
(1.0.0 to 1.2.6, 27 fields)
hyperscsi:
HyperSCSI
(1.0.0 to 1.2.6, 6 fields)
I
ifcp:
iFCP
(1.0.0 to 1.2.6, 21 fields)
ilmi: ILMI
(1.0.0 to 1.2.6, 0 fields)
infiniband:
InfiniBand
(1.0.0 to 1.2.6, 375 fields)
ipars: International Passenger Airline Reservation System
(1.0.0 to 1.2.6, 0 fields)
ipcp: PPP IP Control Protocol
(1.0.0 to 1.2.6, 0 fields)
ipsictl:
IPSICTL
(1.2.0 to 1.2.6, 7 fields)
ipv6cp: PPP IPv6 Control Protocol
(1.0.0 to 1.2.6, 0 fields)
ipxwan:
IPX WAN
(1.0.0 to 1.2.6, 19 fields)
iscsi:
iSCSI
(1.0.0 to 1.2.6, 104 fields)
isdn:
ISDN
(1.0.0 to 1.2.6, 1 field)
isns:
iSNS
(1.0.0 to 1.2.6, 101 fields)
iuup:
IuUP
(1.0.0 to 1.2.6, 1322 fields)
J
juniper:
Juniper
(1.0.0 to 1.2.6, 18 fields)
jxta:
JXTA P2P
(1.0.0 to 1.2.6, 49 fields)
jxta.message: JXTA Message
(1.0.0 to 1.2.6, 0 fields)
K
k12:
K12xx
(1.0.0 to 1.2.6, 6 fields)
kerberos:
Kerberos
(1.0.0 to 1.2.6, 180 fields)
L
lane: ATM LAN Emulation
(1.0.0 to 1.2.6, 0 fields)
laplink:
Laplink
(1.0.0 to 1.2.6, 5 fields)
lcp: PPP Link Control Protocol
(1.0.0 to 1.2.6, 0 fields)
lwapp-cntl: LWAPP Control Message
(1.0.0 to 1.2.6, 0 fields)
lwapp-l3: LWAPP Layer 3 Packet
(1.0.0 to 1.2.6, 0 fields)
M
mac-lte:
MAC-LTE
(1.2.0 to 1.2.6, 58 fields)
malformed: Malformed Packet
(1.0.0 to 1.2.6, 0 fields)
mate: Meta Analysis Tracing Engine
(1.0.0 to 1.2.6, 0 fields)
media: Media Type
(1.0.0 to 1.2.6, 0 fields)
megaco:
MEGACO
(1.0.0 to 1.2.6, 47 fields)
message-http: Media Type: message/http
(1.0.0 to 1.2.6, 0 fields)
mibs:
MIBs
(1.0.3 to 1.0.6, 1.0.9 to 1.2.0, 1.2.1 to 1.2.6, 759 fields)
mms:
MMS
(1.0.0 to 1.2.6, 441 fields)
mp4v-es:
MP4V-ES
(1.2.0 to 1.2.6, 15 fields)
mpeg: Moving Picture Experts Group
(1.0.0 to 1.2.6, 0 fields)
mplscp: PPP MPLS Control Protocol
(1.0.0 to 1.2.6, 0 fields)
msnms: MSN Messenger Service
(1.0.0 to 1.2.6, 0 fields)
N
nbipx: NetBIOS over IPX
(1.0.0 to 1.2.6, 0 fields)
netbios:
NetBIOS
(1.0.0 to 1.2.6, 31 fields)
nfsacl:
NFSACL
(1.0.0 to 1.2.6, 11 fields)
nfsauth:
NFSAUTH
(1.0.0 to 1.2.6, 1 field)
nisplus:
NIS+
(1.0.0 to 1.2.6, 112 fields)
nmpi: Name Management Protocol over IPX
(1.0.0 to 1.2.6, 0 fields)
nw_serial: NetWare Serialization Protocol
(1.0.0 to 1.2.6, 0 fields)
O
oamaal: ATM OAM AAL
(1.0.0 to 1.2.6, 0 fields)
osi: OSI
(1.0.0 to 1.2.6, 0 fields)
osicp: PPP OSI Control Protocol
(1.0.0 to 1.2.6, 0 fields)
P
pap: PPP Password Authentication Protocol
(1.0.0 to 1.2.6, 0 fields)
pcnfsd:
PC NFS
(1.0.0 to 1.2.6, 15 fields)
pdcp-lte:
PDCP-LTE
(1.2.0 to 1.2.6, 86 fields)
pkcs-1:
PKCS#1
(1.0.0 to 1.2.6, 11 fields)
pkinit:
PKINIT
(1.0.0 to 1.2.6, 22 fields)
portmap:
Portmap
(1.0.0 to 1.2.6, 19 fields)
ppp_hdlc: PPP In HDLC-Like Framing
(1.0.0 to 1.2.6, 0 fields)
pppmux: PPP Multiplexing
(1.0.0 to 1.2.6, 0 fields)
pppmuxcp: PPPMux Control Protocol
(1.0.0 to 1.2.6, 0 fields)
pw_atm_n2o_nocw: ATM PW, N-to-one Cell Mode (no CW)
(1.2.0 to 1.2.6, 0 fields)
pw_hdlc_nocw_hdlc_ppp: HDLC-like framing for PPP
(1.2.0 to 1.2.6, 0 fields)
pwach: PW Associated Channel Header
(1.2.0 to 1.2.6, 0 fields)
pwethheuristic: Ethernet PW (CW heuristic)
(1.2.0 to 1.2.6, 0 fields)
pwethnocw: Ethernet PW (no CW)
(1.2.0 to 1.2.6, 0 fields)
pwmcw: PW MPLS Control Word (generic/preferred)
(1.2.0 to 1.2.6, 0 fields)
Q
q2931:
Q.2931
(1.0.0 to 1.2.6, 9 fields)
q931:
Q.931
(1.0.0 to 1.2.6, 40 fields)
q932:
Q.932
(1.0.0 to 1.2.6, 39 fields)
q933:
Q.933
(1.0.0 to 1.2.6, 23 fields)
qsig:
QSIG
(1.0.0 to 1.2.6, 744 fields)
R
radio: 802.11 radio information
(1.0.0 to 1.2.6, 0 fields)
raw: Raw packet data
(1.0.0 to 1.2.6, 0 fields)
raw_sigcomp: Decompressed SigComp message as raw text
(1.0.0 to 1.2.6, 0 fields)
redback:
Redback
(1.0.0 to 1.2.6, 9 fields)
remunk2: IRemUnknown2
(1.0.0 to 1.2.6, 0 fields)
ripng:
RIPng
(1.0.0 to 1.2.6, 2 fields)
rlc-lte:
RLC-LTE
(1.2.0 to 1.2.6, 41 fields)
rmi:
Java RMI
(1.0.0 to 1.2.6, 10 fields)
rss:
rss
(1.0.0 to 1.2.6, 122 fields)
rstat:
RSTAT
(1.0.0 to 1.2.6, 4 fields)
rtcfg:
RTcfg
(1.0.0 to 1.2.6, 23 fields)
S
sadmind:
SADMIND
(1.0.0 to 1.2.6, 3 fields)
scsi:
SCSI
(1.0.0 to 1.2.6, 174 fields)
scsi_mmc:
SCSI_MMC
(1.0.0 to 1.2.6, 120 fields)
scsi_osd:
SCSI_OSD
(1.0.0 to 1.2.6, 82 fields)
scsi_sbc:
SCSI_SBC
(1.0.0 to 1.2.6, 72 fields)
scsi_smc:
SCSI_SMC
(1.0.0 to 1.2.6, 17 fields)
scsi_ssc:
SCSI_SSC
(1.0.0 to 1.2.6, 41 fields)
serialization: Java Serialization
(1.0.0 to 1.2.6, 0 fields)
sgimount: SGI Mount Service
(1.0.0 to 1.2.6, 0 fields)
short: Short Frame
(1.0.0 to 1.2.6, 0 fields)
sipfrag:
Sipfrag
(1.0.0 to 1.2.6, 1 field)
sna_xid: Systems Network Architecture XID
(1.0.0 to 1.2.6, 0 fields)
spnego-krb5: SPNEGO-KRB5
(1.0.0 to 1.2.6, 0 fields)
spray:
SPRAY
(1.0.0 to 1.2.6, 6 fields)
sscf-nni:
SSCF-NNI
(1.0.0 to 1.2.6, 2 fields)
sscop:
SSCOP
(1.0.0 to 1.2.6, 8 fields)
starteam:
StarTeam
(1.0.0 to 1.2.6, 17 fields)
synergy:
Synergy
(1.0.0 to 1.2.6, 59 fields)
T
t30:
T.30
(1.0.0 to 1.2.6, 103 fields)
t38:
T.38
(1.0.0 to 1.2.6, 37 fields)
tacacs:
TACACS
(1.0.0 to 1.2.6, 13 fields)
tacplus:
TACACS+
(1.0.0 to 1.2.6, 12 fields)
tdma: TDMA RTmac Discipline
(1.0.0 to 1.2.6, 0 fields)
telnet:
Telnet
(1.0.0 to 1.2.6, 10 fields)
U
udpencap: UDP Encapsulation of IPsec Packets
(1.0.0 to 1.2.6, 0 fields)
unreassembled: Unreassembled Fragmented Packet
(1.0.0 to 1.2.6, 0 fields)
usb:
USB
(1.0.0 to 1.2.6, 72 fields)
user_dlt: DLT User
(1.0.0 to 1.2.6, 0 fields)
V
vcdu:
VCDU
(1.2.0 to 1.2.6, 26 fields)
vines_arp: Banyan Vines ARP
(1.0.0 to 1.2.6, 0 fields)
vines_echo: Banyan Vines Echo
(1.0.0 to 1.2.6, 0 fields)
vines_frp: Banyan Vines Fragmentation Protocol
(1.0.0 to 1.2.6, 0 fields)
vines_icp: Banyan Vines ICP
(1.0.0 to 1.2.6, 0 fields)
vines_ipc: Banyan Vines IPC
(1.0.0 to 1.2.6, 0 fields)
vines_llc: Banyan Vines LLC
(1.0.0 to 1.2.6, 0 fields)
vines_rtp: Banyan Vines RTP
(1.0.0 to 1.2.6, 0 fields)
vines_spp: Banyan Vines SPP
(1.0.0 to 1.2.6, 0 fields)
W
who:
Who
(1.0.0 to 1.2.6, 14 fields)
wpan-nonask-phy: IEEE 802.15.4 Low-Rate Wireless PAN non-ASK PHY
(1.2.0 to 1.2.6, 0 fields)
X
x.25:
X.25
(1.0.0 to 1.2.0, 17 fields)
x.29:
X.29
(1.0.0 to 1.2.0, 3 fields)
x11:
X11
(1.0.0 to 1.2.6, 455 fields)
x25:
X.25
(1.2.0 to 1.2.6, 17 fields)
x29:
X.29
(1.2.0 to 1.2.6, 3 fields)
xyplex:
Xyplex
(1.0.0 to 1.2.6, 6 fields)
Y
Z
zrtp:
ZRTP
(1.2.0 to 1.2.6, 43 fields)