ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Ethereal-users: [Ethereal-users] Display Filter - Byte Offset Notation

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: "Prigge Scott" <PriggeScottM@xxxxxxxxxxxxx>
Date: Wed, 23 Aug 2006 13:08:12 -0500
-------------------
The Ethereal project is being continued at a new site.  Please go to
http://www.wireshark.org and subscribe to wireshark-users@xxxxxxxxxxxxx.
Don't forget to unsubscribe from this list at
http://www.ethereal.com/mailman/listinfo/ethereal-users
-------------------

Using version 0.99.0, and am struggling to create a simple display
filter using byte offset notation. I want to simply capture traffic
where the first two bytes of the source address are 68.154. Shouldn't
this filter be as simple as ip[12:2]==68 154? I've tried lots of
different permutations, but can't get any to work. I have created the
same offset filter in another product, Network Instruments Observer, and
I get the results I would expect.


_______________________________________________
Ethereal-users mailing list
Ethereal-users@xxxxxxxxxxxx
http://www.ethereal.com/mailman/listinfo/ethereal-users