Wireshark-users: Re: [Wireshark-users] Question on filtering
From: Guy Harris <[email protected]>
Date: Fri, 20 Jun 2008 18:58:45 -0700
On Jun 20, 2008, at 5:05 PM, Mark wrote:

Below is an exmpale. The whole string works great until I add the "and no IGMP" when I do that the rest of the statement returns, meaning its not filtered.
not arp and not dns and not ip.addr== and not  
ip.addr== and no IGMP
That filter is rejected by a recent version of Wireshark, and should  
be rejected by all versions of Wireshark unless they have a bug in the  
filtering code; you have to change the stuff at the end to "and not  
igmp" ("not" rather than "no", "igmp" rather than "IGMP") before it's  
Do you not get an error in your version of Wireshark?  If you don't,  
what version is it?
Or did you actually type "not igmp" rather than "no IGMP" in the  
expression you used in Wireshark?