Display Filter Reference: ETW WFP Capture

Protocol field name: etw.wfp_capture

Versions: 2.6.0 to 2.6.5

Back to Display Filter Reference

Field name Description Type Versions
etw.wfp_capture.callout Callout Unsigned integer, 4 bytes 2.6.0 to 2.6.5
etw.wfp_capture.callout_error_message Driver Name Character string 2.6.0 to 2.6.5
etw.wfp_capture.driver_error_message Driver Name Character string 2.6.0 to 2.6.5
etw.wfp_capture.driver_name Driver Name Character string 2.6.0 to 2.6.5
etw.wfp_capture.event_id Event ID Unsigned integer, 4 bytes 2.6.0 to 2.6.5
etw.wfp_capture.filter_id Filter ID Unsigned integer, 8 bytes 2.6.0 to 2.6.5
etw.wfp_capture.filter_weight Filter Weight Unsigned integer, 8 bytes 2.6.0 to 2.6.5
etw.wfp_capture.major_version Major Version Unsigned integer, 2 bytes 2.6.0 to 2.6.5
etw.wfp_capture.minor_version Minor Version Unsigned integer, 2 bytes 2.6.0 to 2.6.5
etw.wfp_capture.nt_status NT Status Unsigned integer, 4 bytes 2.6.0 to 2.6.5
Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
Learn More

Buy Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ AppResponse 11
  • • Full stack analysis – from packets to pages
  • • Rich performance metrics & pre-defined insights for fast problem identification/resolution
  • • Modular, flexible solution for deeply-analyzing network & application performance
Learn More