Wireshark-dev: [Wireshark-dev] how can i find the source code about display filter in wireshark
From: "chunhui CHE" <[email protected]>
Date: Sun, 13 Jan 2008 15:50:19 +0800
hi,all.

i am doing something about network traffic classification. when i use wireshark to collect some training data, i found it didn't work very well, sometimes. for example, when i type " tshark -r <file> -w <file> -R "http" " in command line and get some data about http(Hypertext Transfer Protocol). i found it also contains many p2p traffic. i am wondering how wireshark define the display filter "http". can i get some information about it in the source code? and how? can you tell me in which file?

i am sorry , my English is poor. i hope you all can understand my question, an give some help. thx.

--
Regards.
/jackyche