Wireshark-users: [Wireshark-users] Display Filter - Byte Offset Notation

From: "Prigge Scott" <PriggeScottM@xxxxxxxxxxxxx>
Date: Wed, 23 Aug 2006 15:01:41 -0500
Using version 0.99.2, and am struggling to create a simple display
filter using byte offset notation. I want to simply capture traffic
where the first two bytes of the source address are 68.154. Shouldn't
this filter be as simple as ip[12:2]==68 154? I've tried lots of
different permutations, but can't get any to work. I have created the
same offset filter in another product, Network Instruments Observer, and
I get the results I would expect.