Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] WS version 1.2.0 - TCP Stream Index

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "Sake Blok" <sake@xxxxxxxxxx>
Date: Wed, 8 Jul 2009 16:57:23 +0200

Hi Alex,
 
Correct, I changed the way the Follow TCP stream filters to make it possible to follow a specific stream when multiple streams with the same ip/port combinations are in the same trace.
 
When you right-click in the packet-list and choose "Conversation filter -> TCP", the "old" way is still used and you can copy the filter string.
 
Hope this helps,
Cheers,
 
 
Sake
----- Original Message -----
From: Alex Lee
To: wireshark-users@xxxxxxxxxxxxx
Sent: Monday, July 06, 2009 7:14 PM
Subject: [Wireshark-users] WS version 1.2.0 - TCP Stream Index

Hi Wireshark Community –

 

I just recently upgraded my WS to 1.2.0 and when I do look at traces, I tend to “follow a TCP stream” and typically cut/paste the actual stream _expression_ so that others can view the trace and cut/paste the stream I was referring to.

 

It seems in this new version, it lists stream #’s, for example “tcp.stream eq 2” – I figure this means the second TCP stream, which is great but I prefer the old method where a “follow tcp stream” resulted in the actual _expression_ filter but I can’t seemingly find that option (if it does exist). Any help?

 

Alex

 


___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe
  • References:
    • [Wireshark-users] WS version 1.2.0 - TCP Stream Index
      • From: Alex Lee
  • Prev by Date: Re: [Wireshark-users] Export TCP Stream - RTT Graph Data
  • Next by Date: Re: [Wireshark-users] Auto refresh of the open file
  • Previous by thread: [Wireshark-users] WS version 1.2.0 - TCP Stream Index
  • Next by thread: [Wireshark-users] should Tshark use both the header and payload of MPEG transport stream packet to calculate jitter, delay, packet loss and bandwidth?
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation