Display Filter Reference: PCAPNG File Format

Protocol field name: file-pcapng

Versions: 2.0.0 to 2.6.1

Back to Display Filter Reference

Field name Description Type Versions
pcapng.block Block Label 2.0.0 to 2.6.1
pcapng.block.data Block Data Label 2.0.0 to 2.6.1
pcapng.block.length Block Length Unsigned integer, 4 bytes 2.0.0 to 2.6.1
pcapng.block.type Block Type Unsigned integer, 4 bytes 2.0.0 to 2.6.1
pcapng.block.type.value Block Type Value Unsigned integer, 4 bytes 2.0.0 to 2.6.1
pcapng.block.type.vendor Block Type Vendor Boolean 2.0.0 to 2.6.1
pcapng.darwin.process_id Darwin Process ID Unsigned integer, 4 bytes 2.4.0 to 2.6.1
pcapng.darwin.process_name Darwin Process Name Character string 2.4.0 to 2.6.1
pcapng.darwin.process_uuid Darwin Process UUID Globally Unique Identifier 2.4.0 to 2.6.1
pcapng.interface_description.link_type Link Type Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.interface_description.reserved Reserved Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.interface_description.snap_length Snap Length Unsigned integer, 4 bytes 2.0.0 to 2.6.1
pcapng.interface_id Interface Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.invalid_option_length Invalid Option Length Label 2.0.0 to 2.6.1
pcapng.invalid_record_length Invalid Record Length Label 2.0.0 to 2.6.1
pcapng.options Options Label 2.0.0 to 2.6.1
pcapng.options.option Option Label 2.0.0 to 2.6.1
pcapng.options.option.code Code Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.options.option.data Option Data Label 2.0.0 to 2.6.1
pcapng.options.option.data.comment Comment Character string 2.0.0 to 2.6.1
pcapng.options.option.data.dns_name DNS Name Character string 2.0.0 to 2.6.1
pcapng.options.option.data.end_time End Time Label 2.0.0 to 2.6.1
pcapng.options.option.data.eui EUI Address EUI64 address 2.0.0 to 2.6.1
pcapng.options.option.data.hardware Hardware Character string 2.0.0 to 2.6.1
pcapng.options.option.data.interface.accepted_by_filter Number of Accepted by Filter Packets Unsigned integer, 8 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.interface.delivered_to_user Number of Delivered to the User Packets Unsigned integer, 8 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.interface.description Description Character string 2.0.0 to 2.6.1
pcapng.options.option.data.interface.dropped Number of Dropped Packets Unsigned integer, 8 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.interface.dropped_by_os Number of Dropped Packets by OS Unsigned integer, 8 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.interface.fcs_length FCS Length Unsigned integer, 1 byte 2.0.0 to 2.6.1
pcapng.options.option.data.interface.filter Filter Character string 2.0.0 to 2.6.1
pcapng.options.option.data.interface.name Name Character string 2.0.0 to 2.6.1
pcapng.options.option.data.interface.os OS Character string 2.0.0 to 2.6.1
pcapng.options.option.data.interface.received Number of Received Packets Unsigned integer, 8 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.interface.speed Speed Unsigned integer, 8 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.interface.timestamp_offset Timestamp Offset Unsigned integer, 8 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.interface.timestamp_resolution Timestamp Resolution Unsigned integer, 1 byte 2.0.0 to 2.6.1
pcapng.options.option.data.interface.timestamp_resolution.base Base Unsigned integer, 1 byte 2.0.0 to 2.6.1
pcapng.options.option.data.interface.timestamp_resolution.value Value Unsigned integer, 1 byte 2.0.0 to 2.6.1
pcapng.options.option.data.interface.timezone Timezone Unsigned integer, 4 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.ipv4 IPv4 IPv4 address 2.0.0 to 2.6.1
pcapng.options.option.data.ipv4_mask IPv4 Mask IPv4 address 2.0.0 to 2.6.1
pcapng.options.option.data.ipv6 IPv6 IPv6 address 2.2.0 to 2.6.1
pcapng.options.option.data.ipv6_mask IPv6 Mask Unsigned integer, 1 byte 2.0.0 to 2.6.1
pcapng.options.option.data.mac MAC Address Ethernet or other MAC address 2.0.0 to 2.6.1
pcapng.options.option.data.os OS Character string 2.0.0 to 2.6.1
pcapng.options.option.data.packet.darwin.dpeb_id DPEB ID Unsigned integer, 4 bytes 2.4.0 to 2.6.1
pcapng.options.option.data.packet.darwin.edpeb_id Effective DPED ID Unsigned integer, 4 bytes 2.4.0 to 2.6.1
pcapng.options.option.data.packet.darwin.svc_class Darwin svc Unsigned integer, 4 bytes 2.4.0 to 2.6.1
pcapng.options.option.data.packet.drop_count Drop Count Unsigned integer, 8 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.packet.flags Flags Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.packet.flags.direction Direction Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.packet.flags.fcs_length FCS Length Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.packet.flags.link_layer_errors Link Layer Errors Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.packet.flags.link_layer_errors.crc CRC Error Boolean 2.0.0 to 2.6.1
pcapng.options.option.data.packet.flags.link_layer_errors.packet_too_long Packet Too Long Boolean 2.0.0 to 2.6.1
pcapng.options.option.data.packet.flags.link_layer_errors.packet_too_short Packet Too Short Boolean 2.0.0 to 2.6.1
pcapng.options.option.data.packet.flags.link_layer_errors.preamble Preamble Error Boolean 2.0.0 to 2.6.1
pcapng.options.option.data.packet.flags.link_layer_errors.reserved Reserved Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.packet.flags.link_layer_errors.start_frame_delimiter Start Frame Delimiter Error Boolean 2.0.15 to 2.0.16, 2.2.9 to 2.2.15, 2.4.1 to 2.6.1
pcapng.options.option.data.packet.flags.link_layer_errors.symbol Symbol Error Boolean 2.0.0 to 2.6.1
pcapng.options.option.data.packet.flags.link_layer_errors.unaligned_frame Unaligned Frame Error Boolean 2.0.15 to 2.0.16, 2.2.9 to 2.2.15, 2.4.1 to 2.6.1
pcapng.options.option.data.packet.flags.link_layer_errors.wrong_inter_frame_gap Wrong Inter Frame Gap Boolean 2.0.0 to 2.6.1
pcapng.options.option.data.packet.flags.reception_type Reception Type Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.packet.flags.reserved Reserved Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.options.option.data.packet.hash.algorithm Hash Algorithm Unsigned integer, 1 byte 2.0.0 to 2.6.1
pcapng.options.option.data.packet.hash.data Hash Data Sequence of bytes 2.0.0 to 2.6.1
pcapng.options.option.data.start_time Start Time Label 2.0.0 to 2.6.1
pcapng.options.option.data.user_application User Application Character string 2.0.0 to 2.6.1
pcapng.options.option.length Length Signed integer, 8 bytes 2.0.0 to 2.6.1
pcapng.options.option.padding Option Padding Label 2.0.0 to 2.6.1
pcapng.packet.captured_length Captured Length Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.packet.drops_count Drops Count Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.packet.interface_id Interface Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.packet.packet_data Packet Data Label 2.0.0 to 2.6.1
pcapng.packet.packet_length Packet Length Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.packet.padding Packet Padding Label 2.0.0 to 2.6.1
pcapng.records Records Label 2.0.0 to 2.6.1
pcapng.records.record Record Label 2.0.0 to 2.6.1
pcapng.records.record.code Code Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.records.record.data Record Data Label 2.0.0 to 2.6.1
pcapng.records.record.data.ipv4 IPv4 IPv4 address 2.0.0 to 2.6.1
pcapng.records.record.data.ipv6 IPv6 IPv6 address 2.0.0 to 2.6.1
pcapng.records.record.data.name Name Character string 2.0.0 to 2.6.1
pcapng.records.record.length Length Signed integer, 8 bytes 2.0.0 to 2.6.1
pcapng.records.record.padding Record Padding Label 2.0.0 to 2.6.1
pcapng.section_header.byte_order_magic Byte Order Magic Sequence of bytes 2.0.0 to 2.6.1
pcapng.section_header.section_length Section Length Signed integer, 8 bytes 2.0.0 to 2.6.1
pcapng.section_header.version.major Major Version Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.section_header.version.minor Minor Version Unsigned integer, 2 bytes 2.0.0 to 2.6.1
pcapng.timestamp Timestamp Date and time 2.0.0 to 2.6.1
pcapng.timestamp_high Timestamp (High) Unsigned integer, 4 bytes 2.0.0 to 2.6.1
pcapng.timestamp_low Timestamp (Low) Unsigned integer, 4 bytes 2.0.0 to 2.6.1
pcapng.unknown_encoding Expert Info Label 2.0.0 to 2.0.1
Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
Learn More

Buy Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ NetShark appliance
  • • Troubleshoot problems faster
  • • Quickly identify the applications running on your network
  • • Monitor your virtual machine traffic
Learn More