ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Wireshark-users: Re: [Wireshark-users] Wireshark Capture Filter Using Offset

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Mon, 19 Jul 2010 23:25:28 -0700
On Jul 19, 2010, at 9:32 PM, j.snelders wrote:

> I think  the capture filter should be (but can't test it right now):
> dns[2:2]==0x2800

libpcap doesn't know about DNS, so that doesn't work.