Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Display Filter Reference: Who

Protocol field name: who
Versions: 1.0.0 to 1.6.5

Back to Display Filter Reference

Field name Type Description Versions
who.boottime Date and time Boot Time 1.0.0 to 1.6.5
who.hostname Character string Hostname 1.0.0 to 1.6.5
who.idle Unsigned integer, 4 bytes Time Idle 1.0.0 to 1.6.5
who.loadav_10 Floating point (double-precision) Load Average Over Past 10 Minutes 1.0.0 to 1.6.5
who.loadav_15 Floating point (double-precision) Load Average Over Past 15 Minutes 1.0.0 to 1.6.5
who.loadav_5 Floating point (double-precision) Load Average Over Past 5 Minutes 1.0.0 to 1.6.5
who.recvtime Date and time Receive Time 1.0.0 to 1.6.5
who.sendtime Date and time Send Time 1.0.0 to 1.6.5
who.timeon Date and time Time On 1.0.0 to 1.6.5
who.tty Character string TTY Name 1.0.0 to 1.6.5
who.type Unsigned integer, 1 byte Type 1.0.0 to 1.6.5
who.uid Character string User ID 1.0.0 to 1.6.5
who.vers Unsigned integer, 1 byte Version 1.0.0 to 1.6.5
who.whoent Label Who utmp Entry 1.0.0 to 1.6.5

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation