Wireshark

  • Riverbed Technology
  • WinPcap
SHARKFEST '13 - Wireshark Developer and User Conference - June 16-19, 2013 - UC Berkeley
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] filter one ip while excluding another

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "Tony" <tonj@xxxxxxxxxx>
Date: Thu, 10 Sep 2009 10:02:59 +0100

Tim thanks very much for your feedback.

----- Original Message ----- From: <Tim.Poth@xxxxxxxxxxx>
To: <wireshark-users@xxxxxxxxxxxxx>
Sent: Wednesday, September 09, 2009 9:29 PM
Subject: Re: [Wireshark-users] filter one ip while excluding another


Ip.addr eq 10.0.0.1 and !ip.addr eq 10.0.0.5

-----Original Message-----
From: wireshark-users-bounces@xxxxxxxxxxxxx [mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Tony
Sent: Wednesday, September 09, 2009 4:23 PM
To: wireshark-users@xxxxxxxxxxxxx
Subject: [Wireshark-users] filter one ip while excluding another

wireshark v1.0.4

I'm new to these forums so hi.
I need to know the expression to use in wireshark to:
1) filter on one ip address while excluding another.
eg: I want to filter ip address 10.0.0.1 (easy I know - ip.addr eq
10.0.0.1) but at the same time I want to exclude ip 10.0.0.5 from the
readout. What's the expression to do this? I've been trawling google but
I
can't find the answer. Thanks for any pointers.


___________________________________________________________________________
Sent via: Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users

mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe
___________________________________________________________________________
Sent via: Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users

mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe




  • References:
    • [Wireshark-users] filter one ip while excluding another
      • From: Tony
    • Re: [Wireshark-users] filter one ip while excluding another
      • From: Tim.Poth
  • Prev by Date: Re: [Wireshark-users] MacOS 10.6 / Wireshark 1.2.1 - No interfaces to capture from is listed..
  • Next by Date: [Wireshark-users] Why does wireshark not recognize my RTP packets in the correct way?
  • Previous by thread: Re: [Wireshark-users] filter one ip while excluding another
  • Next by thread: [Wireshark-users] Why does wireshark not recognize my RTP packets in the correct way?
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation