Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: Re: [Wireshark-dev] Byte matching

From: Jeff Morriss <jeff.morriss.ws@xxxxxxxxx>
Date: Tue, 27 May 2014 16:39:36 -0400
On 05/26/14 04:07, Matteo Pelliccia wrote:
Hi to all,
maybe it's a silly question. Is it possibile to know what byte match in
display filter expression? For example if I have a pcap file with some
packet and I run tshark with -Y option I would like to know which bytes
match that expression, is it possibile?

Unfortunately no, not today. There's been some discussion of highlighting the field (if not the bytes) in the GUI (there's probably a bug requesting that) but this is the first time I've heard of it for tshark.