Display Filter Reference: User Datagram Protocol

Protocol field name: udp

Versions: 1.0.0 to 2.6.4

Back to Display Filter Reference

Field name Description Type Versions
udp.checksum Checksum Unsigned integer, 2 bytes 1.0.0 to 2.6.4
udp.checksum.bad Bad checksum Label 2.0.0 to 2.6.4
udp.checksum.status Checksum Status Unsigned integer, 1 byte 2.2.0 to 2.6.4
udp.checksum.zero Illegal Checksum value (0) Label 1.12.0 to 2.6.4
udp.checksum_bad Bad Checksum Boolean 1.0.0 to 2.0.16
udp.checksum_bad.expert Expert Info Label 1.12.0 to 1.12.13
udp.checksum_calculated Calculated Checksum Unsigned integer, 2 bytes 1.12.0 to 2.6.4
udp.checksum_coverage.expert Expert Info Label 1.12.0 to 1.12.13
udp.checksum_good Good Checksum Boolean 1.0.0 to 2.0.16
udp.dstport Destination Port Unsigned integer, 2 bytes 1.0.0 to 2.6.4
udp.length Length Unsigned integer, 2 bytes 1.0.0 to 2.6.4
udp.length.bad Bad length value Label 1.12.0 to 2.6.4
udp.length.bad_zero Length is zero but payload < 65536 Label 2.0.0 to 2.6.4
udp.pdu.size PDU Size Unsigned integer, 4 bytes 2.0.0 to 2.6.4
udp.port Source or Destination Port Unsigned integer, 2 bytes 1.0.0 to 2.6.4
udp.possible_traceroute Possible traceroute Label 1.12.0 to 2.6.4
udp.proc.dstcmd Destination process name Character string 1.2.0 to 2.6.4
udp.proc.dstpid Destination process ID Unsigned integer, 4 bytes 1.2.0 to 2.6.4
udp.proc.dstuid Destination process user ID Unsigned integer, 4 bytes 1.2.0 to 2.6.4
udp.proc.dstuname Destination process user name Character string 1.2.0 to 2.6.4
udp.proc.srccmd Source process name Character string 1.2.0 to 2.6.4
udp.proc.srcpid Source process ID Unsigned integer, 4 bytes 1.2.0 to 2.6.4
udp.proc.srcuid Source process user ID Unsigned integer, 4 bytes 1.2.0 to 2.6.4
udp.proc.srcuname Source process user name Character string 1.2.0 to 2.6.4
udp.srcport Source Port Unsigned integer, 2 bytes 1.0.0 to 2.6.4
udp.stream Stream index Unsigned integer, 4 bytes 1.12.0 to 2.6.4
udplite.checksum_coverage.bad Bad checksum coverage length value Label 2.0.0 to 2.6.4
Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
Learn More

Buy Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ AppResponse 11
  • • Full stack analysis – from packets to pages
  • • Rich performance metrics & pre-defined insights for fast problem identification/resolution
  • • Modular, flexible solution for deeply-analyzing network & application performance
Learn More