Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: [Wireshark-users] Capture Filter Help

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: James Pifer <jep@xxxxxxxxxxxxxxxx>
Date: Wed, 06 Feb 2008 13:51:43 -0500

Hi. I've been googling and using the wiki but I can't figure out if this
is possible. 

I'm trying setup a capture filter to capture only data where the ip
address contains a certain part of an ip address. We have a lot of
servers on a distributed network that have standard addresses. 

For example, I'd like to capture data on port 137 if the ip address is
like 192.xxx.xxx.11 where xxx can be anything. 

Can this be done in a capture filter? Looks like it can be done in a
display filter, but I really don't want that. 

Any help is appreciated. 

Thanks,
James


  • Follow-Ups:
    • Re: [Wireshark-users] Capture Filter Help
      • From: Sake Blok
    • Re: [Wireshark-users] Capture Filter Help
      • From: Guy Harris
  • Prev by Date: [Wireshark-users] Counting packets with a matching payload
  • Next by Date: Re: [Wireshark-users] Capture Filter Help
  • Previous by thread: Re: [Wireshark-users] Counting packets with a matching payload
  • Next by thread: Re: [Wireshark-users] Capture Filter Help
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation