We're now a non-profit! Support open source packet analysis by making a donation.

Display Filter Reference: PCAP File Format

Protocol field name: file-pcap

Versions: 2.0.0 to 4.0.6

Back to Display Filter Reference

Field name Description Type Versions
pcap.headerHeaderLabel2.0.0 to 4.0.6
pcap.header.link_typeLink TypeUnsigned integer (32 bits)2.0.0 to 4.0.6
pcap.header.magic_bytesMagic BytesUnsigned integer (32 bits)2.0.0 to 2.0.1
pcap.header.magic_numberMagic NumberByte sequence2.0.2 to 4.0.6
pcap.header.sigfigsSigfigsUnsigned integer (32 bits)2.0.0 to 4.0.6
pcap.header.snapshot_lengthSnapshot LengthUnsigned integer (32 bits)2.0.0 to 4.0.6
pcap.header.this_zoneThis ZoneSigned integer (32 bits)2.0.0 to 4.0.6
pcap.header.version.majorVersion MajorUnsigned integer (16 bits)2.0.0 to 4.0.6
pcap.header.version.minorVersion MinorUnsigned integer (16 bits)2.0.0 to 4.0.6
pcap.inc_len_larger_than_orig_lenincluded length is larger than original lengthLabel3.0.0 to 4.0.6
pcap.inc_len_larger_than_snap_lenincluded length is larger than snapshot lengthLabel3.0.0 to 4.0.6
pcap.packetPacketLabel2.0.0 to 4.0.6
pcap.packet.dataDataLabel2.0.0 to 4.0.6
pcap.packet.data.dataDataLabel2.0.0 to 2.0.16
pcap.packet.data.pseudoheaderPseudoheaderLabel2.0.0 to 2.0.16
pcap.packet.data.pseudoheader.bluetooth.directionDirectionUnsigned integer (32 bits)2.0.0 to 2.0.16
pcap.packet.included_lengthIncluded LengthUnsigned integer (32 bits)2.0.0 to 4.0.6
pcap.packet.origin_lengthOrigin LengthUnsigned integer (32 bits)2.0.0 to 4.0.6
pcap.packet.timestampTimestampDate and time2.0.0 to 4.0.6
pcap.packet.timestamp.secTimestamp secUnsigned integer (32 bits)2.0.0 to 4.0.6
pcap.packet.timestamp.usecTimestamp usecUnsigned integer (32 bits)2.0.0 to 4.0.6
pcap.unknown_encodingExpert InfoLabel2.0.0 to 2.0.1