Wireshark-users: [Wireshark-users] list of display filters?
From: "Tennis Smith" <[email protected]>
Date: Wed, 25 Jun 2008 14:06:37 -0500



Sorry for the newbie question, but I’ve just started using TShark.


How can I figure out all the fields which can be displayed in a protocol?  For example, I know that “ip.address” can be filtered out, but what other “ip.<?>” fields are available for use?


I’m looking at a protocol I’m not very familiar with.  I’m looking for some way to list what can be displayed.