Display Filter Reference: User Datagram Protocol

Protocol field name: udp

Versions: 1.0.0 to 2.2.7

Back to Display Filter Reference

Field name Description Type Versions
udp.checksum Checksum Unsigned integer, 2 bytes 1.0.0 to 2.2.7
udp.checksum.bad Expert Info Label 2.0.0 to 2.2.7
udp.checksum.status Checksum Status Unsigned integer, 1 byte 2.2.0 to 2.2.7
udp.checksum.zero Expert Info Label 1.12.0 to 2.2.7
udp.checksum_bad Bad Checksum Boolean 1.0.0 to 2.0.13
udp.checksum_bad.expert Expert Info Label 1.12.0 to 1.12.13
udp.checksum_calculated Calculated Checksum Unsigned integer, 2 bytes 1.12.0 to 2.2.7
udp.checksum_coverage.expert Expert Info Label 1.12.0 to 1.12.13
udp.checksum_good Good Checksum Boolean 1.0.0 to 2.0.13
udp.dstport Destination Port Unsigned integer, 2 bytes 1.0.0 to 2.2.7
udp.length Length Unsigned integer, 2 bytes 1.0.0 to 2.2.7
udp.length.bad Expert Info Label 1.12.0 to 2.2.7
udp.length.bad_zero Expert Info Label 2.0.0 to 2.2.7
udp.pdu.size PDU Size Unsigned integer, 4 bytes 2.0.0 to 2.2.7
udp.port Source or Destination Port Unsigned integer, 2 bytes 1.0.0 to 2.2.7
udp.possible_traceroute Expert Info Label 1.12.0 to 2.2.7
udp.proc.dstcmd Destination process name Character string 1.2.0 to 2.2.7
udp.proc.dstpid Destination process ID Unsigned integer, 4 bytes 1.2.0 to 2.2.7
udp.proc.dstuid Destination process user ID Unsigned integer, 4 bytes 1.2.0 to 2.2.7
udp.proc.dstuname Destination process user name Character string 1.2.0 to 2.2.7
udp.proc.srccmd Source process name Character string 1.2.0 to 2.2.7
udp.proc.srcpid Source process ID Unsigned integer, 4 bytes 1.2.0 to 2.2.7
udp.proc.srcuid Source process user ID Unsigned integer, 4 bytes 1.2.0 to 2.2.7
udp.proc.srcuname Source process user name Character string 1.2.0 to 2.2.7
udp.srcport Source Port Unsigned integer, 2 bytes 1.0.0 to 2.2.7
udp.stream Stream index Unsigned integer, 4 bytes 1.12.0 to 2.2.7
udplite.checksum_coverage.bad Expert Info Label 2.0.0 to 2.2.7
Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
  • • Fully integrated with Wireshark and AirPcap™
Learn More

Buy Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ NetShark appliance
  • • Troubleshoot problems faster
  • • Quickly identify the applications running on your network
  • • Monitor your virtual machine traffic
Learn More

I need to capture wireless traffic...

ANSWER: AirPcap™ 802.11 Packet Capture
  • • WLAN packet capture and transmission
  • • Full 802.11 a/b/g/n support
  • • View management, control and data frames
  • • Multi-channel aggregation (with multiple adapters)
Learn More Buy Now