Display Filter Reference: File

Protocol field name: file

Versions: 1.12.0 to 2.6.3

Back to Display Filter Reference

Field name Description Type Versions
file.coloring_rule.name Coloring Rule Name Character string 1.12.0 to 2.6.3
file.coloring_rule.string Coloring Rule String Character string 1.12.0 to 2.6.3
file.encap_type Encapsulation type Signed integer, 2 bytes 1.12.0 to 2.6.3
file.ignored File record is ignored Boolean 1.12.0 to 2.6.3
file.marked File record is marked Boolean 1.12.0 to 2.6.3
file.p_record_data Number of per-record-data Unsigned integer, 4 bytes 1.12.0 to 2.6.3
file.proto_name_and_key Protocol Name and Key Character string 2.0.0 to 2.6.3
file.record_len Record length Unsigned integer, 4 bytes 1.12.0 to 2.6.3
file.record_number Record Number Unsigned integer, 4 bytes 1.12.0 to 2.6.3
file.record_types File record types in frame Character string 1.12.0 to 2.6.3
Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
Learn More

Buy Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ AppResponse 11
  • • Full stack analysis – from packets to pages
  • • Rich performance metrics & pre-defined insights for fast problem identification/resolution
  • • Modular, flexible solution for deeply-analyzing network & application performance
Learn More