Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: [Wireshark-dev] RFC: New "Conversation Filter" entry in the context menu of the

From: Ulf Lamping <ulf.lamping@xxxxxx>
Date: Sun, 13 Aug 2006 00:51:58 +0200
Hi List!

I've just added a new entry to the packet list context menu: "Conversation Filter".

Since I've implemented this some weeks ago, I've worked with it and found it very helpful in the everyday work.

What it will do:

If you select a packet and then use the context menu, you'll see the following subentries:

- Ethernet
- IP
- TCP
- UDP
- PN-CBA Server (very PROFINET specific)

An entry will only be selectable, if the selected packet contains that protocol.

If used, Wireshark will create the corresponding filter to the packet and will apply it, e.g. TCP will apply a filter with the same IP addresses and TCP ports.

We might want to enhance this with other possibilities like "not TCP", "Prepare TCP" and alike and for other protocols as well.

Motivation: I've often saw people using the "Follow TCP stream" function "only" to filter the TCP stream, closing the upcoming dialog right after it's shown.

The "Conversation Filter" will do the filter functionality in a similar way for other protocols, and simplify the handling for the TCP protocol in these cases.

Looking for comments,

Regards, ULFL