Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Display Filter Reference: Linux cooked-mode capture

Protocol field name: sll
Versions: 1.0.0 to 1.6.5

Back to Display Filter Reference

Field name Type Description Versions
sll.etype Unsigned integer, 2 bytes Protocol 1.0.0 to 1.6.5
sll.gretype Unsigned integer, 2 bytes Protocol 1.0.0 to 1.6.5
sll.halen Unsigned integer, 2 bytes Link-layer address length 1.0.0 to 1.6.5
sll.hatype Unsigned integer, 2 bytes Link-layer address type 1.0.0 to 1.6.5
sll.ltype Unsigned integer, 2 bytes Protocol 1.0.0 to 1.6.5
sll.pkttype Unsigned integer, 2 bytes Packet type 1.0.0 to 1.6.5
sll.src.eth Ethernet or other MAC address Source 1.0.0 to 1.6.5
sll.src.ipv4 IPv4 address Source 1.0.0 to 1.6.5
sll.src.other Sequence of bytes Source 1.0.0 to 1.6.5
sll.trailer Sequence of bytes Trailer 1.0.0 to 1.6.5

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation