We're now a non-profit! Support open source packet analysis by making a donation.

Wireshark-users: Re: [Wireshark-users] how to filter a port?

From: "David Drexler" <xxyokc@xxxxxxxxx>
Date: Mon, 26 Feb 2007 00:10:34 -0600
It's either to or from 'http'.  I also tried

tcp.port != 80

same results.  I want to run the capture realtime and only see the traffic that interests me.


On 2/25/07, Jeff Morriss <jeff.morriss@xxxxxxxxxxx> wrote:

David Drexler wrote:
> I'm running the latest wireshark and winpcap.  I want to capture
> everything except http traffic.  Seems like
> not port 80
> would do it - but it doesn't, I still see lots of http.  What am I doing
> wrong?

That's a capture filter to eliminate things on TCP (and UDP) port 80.
Is the HTTP traffic you're seeing on a different port?

If so, you could try a display filter (applied after the capture is
done) like "!http".

Wireshark-users mailing list