Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Capture filter

From: Pedro Tumusok <pedro.tumusok@xxxxxxxxx>
Date: Wed, 28 Jan 2009 13:33:28 +0100
On Wed, Jan 28, 2009 at 1:20 PM, Rene Forstner <rene.forstner@xxxxxx> wrote:
> Hi,
>
> I'm using Wireshark v1.0.4 on Win XP SP2 since a few days, so i'm new at
> this area.
> In the faq and the wiki i did'nt find any answer. So I hope I'm right here.
>
> I wan't to know if it is possible to configure the capture filter that
> wireshark captures only the traffic caused by a few ip-adresses.
>
> The ip's are'nt in the same subnet so "net 1.2.3.4/24" or something like
> this does not work
>
>

I'm no guru, but I think the following should work.

host ip1 or host ip2 or host ip3



-- 
Best regards / Mvh
Jan Pedro Tumusok

I know you love me
And you want to be Friends
And if you dont
at least you need to pretend